Compromised Salesloft Drift Tokens Enable Data Theft Across Integrations (Campaign)
ID: 1e1b50ac-bfd3-544f-86f6-65cda1273d66
STIX ID: report--1e1b50ac-bfd3-544f-86f6-65cda1273d66
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-09-02
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
Google Threat Intelligence Group reported an active campaign abusing OAuth tokens tied to the Salesloft Drift app to exfiltrate data from Salesforce orgs (observed Aug 8–18, 2025) and a small number of Google Workspace mailboxes via the Drift Email integration; Google, Salesforce, and Salesloft revoked affected tokens and removed integrations, and organizations are advised to treat any Drift-connected authentication tokens as compromised and revoke/rotate all OAuth tokens, API keys, and credentials for third-party apps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
