logo

When trust turns toxic: Lessons from the Salesloft Drift incident

ID: 466a8bc9-c637-5bd7-8b77-674d6a035a5a

STIX ID: report--466a8bc9-c637-5bd7-8b77-674d6a035a5a

Feed Name: CyberScoop

Threat Score
78/100

Date Published: 2025-11-24

Date Updated: 2026-04-21

Author: Greg Otto

...
...

The article analyzes the Salesloft/Drift breach where attackers leveraged a compromised Drift chatbot to steal OAuth tokens and access CRM data across more than 700 organizations, exposing sensitive records and embedded credentials. It warns that the deeper issue is identity and permission sprawl from long-lived, over-permissioned integrations and advocates for hygiene (token rotation, least privilege), runtime authorization, ephemeral identities (Zero Standing Privileges), and treating all integrations as governed identities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.