logo

Widespread Salesforce Data Theft via Compromised Salesloft Drift OAuth Tokens

ID: acbd16fd-b150-5fb7-a018-5a805142dad4

STIX ID: report--acbd16fd-b150-5fb7-a018-5a805142dad4

Feed Name: Arctic Wolf

Threat Score
70/100

Date Published: 2025-08-27

Date Updated: 2026-07-26

Author: Andres Ramos

...
...

On 20–26 August 2025, Salesloft and Google Threat Intelligence Group reported that UNC6395 abused compromised OAuth tokens tied to the Salesloft Drift integration to access multiple corporate Salesforce instances and exfiltrate large volumes of data—primarily credential material such as AWS keys, passwords, and Snowflake tokens. Salesloft and Salesforce proactively revoked all Drift access and refresh tokens, advised impacted customers to open support cases and rotate exposed credentials, and published remediation guidance and updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.