Widespread Salesforce Data Theft via Compromised Salesloft Drift OAuth Tokens
ID: 9124c768-b48d-5664-b82f-1446b59c9f35
STIX ID: report--9124c768-b48d-5664-b82f-1446b59c9f35
Feed Name: Arctic Wolf
On August 8–18, 2025, threat actor UNC6395 used compromised OAuth tokens tied to the Salesloft Drift integration to access multiple corporate Salesforce instances and exfiltrate large volumes of sensitive data (AWS keys, passwords, Snowflake tokens). Salesloft and Salesforce revoked all active Drift access and refresh tokens, are contacting affected customers to investigate, and recommend re-authentication of the integration and rotation of exposed credentials; Google Threat Intelligence Group and Salesloft have published remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
