When SaaS Trust Becomes a Threat: Insights from the Salesloft Drift Compromise
ID: bb6bf489-6ab8-504c-a65f-4cbe2f757548
STIX ID: report--bb6bf489-6ab8-504c-a65f-4cbe2f757548
Feed Name: SecurityScorecard Blog
SecurityScorecard's STRIKE team describes a Salesloft breach where threat actors accessed Salesloft's GitHub and Drift's AWS to steal OAuth tokens from a Drift–Salesforce integration, enabling Salesforce API queries and exfiltration of customer contact and support data; the advisory maps MITRE ATT&CK techniques (e.g., T1199, T1550.001, T1213, T1567), warns of near-term phishing and social-engineering follow-on risk, and recommends revoking/rotating tokens, reviewing API/audit logs, and strengthening email defenses and training.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
