Widespread Salesforce Data Theft via Compromised Salesloft Drift OAuth Tokens
ID: acbd16fd-b150-5fb7-a018-5a805142dad4
STIX ID: report--acbd16fd-b150-5fb7-a018-5a805142dad4
Feed Name: Arctic Wolf
On 20–26 August 2025, Salesloft and Google Threat Intelligence Group reported that UNC6395 abused compromised OAuth tokens tied to the Salesloft Drift integration to access multiple corporate Salesforce instances and exfiltrate large volumes of data—primarily credential material such as AWS keys, passwords, and Snowflake tokens. Salesloft and Salesforce proactively revoked all Drift access and refresh tokens, advised impacted customers to open support cases and rotate exposed credentials, and published remediation guidance and updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
