When trust turns toxic: Lessons from the Salesloft Drift incident
ID: 466a8bc9-c637-5bd7-8b77-674d6a035a5a
STIX ID: report--466a8bc9-c637-5bd7-8b77-674d6a035a5a
Feed Name: CyberScoop
The article analyzes the Salesloft/Drift breach where attackers leveraged a compromised Drift chatbot to steal OAuth tokens and access CRM data across more than 700 organizations, exposing sensitive records and embedded credentials. It warns that the deeper issue is identity and permission sprawl from long-lived, over-permissioned integrations and advocates for hygiene (token rotation, least privilege), runtime authorization, ephemeral identities (Zero Standing Privileges), and treating all integrations as governed identities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
