logo

Widespread Salesforce Data Theft via Compromised Salesloft Drift OAuth Tokens

ID: 9124c768-b48d-5664-b82f-1446b59c9f35

STIX ID: report--9124c768-b48d-5664-b82f-1446b59c9f35

Feed Name: Arctic Wolf

Threat Score
70/100

Date Published: 2025-08-27

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

On August 8–18, 2025, threat actor UNC6395 used compromised OAuth tokens tied to the Salesloft Drift integration to access multiple corporate Salesforce instances and exfiltrate large volumes of sensitive data (AWS keys, passwords, Snowflake tokens). Salesloft and Salesforce revoked all active Drift access and refresh tokens, are contacting affected customers to investigate, and recommend re-authentication of the integration and rotation of exposed credentials; Google Threat Intelligence Group and Salesloft have published remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.