logo

Google: Salesforce Attacks Stemmed From Third-Party App

ID: 5d08022f-4a3d-5c92-9075-709a1b0402cc

STIX ID: report--5d08022f-4a3d-5c92-9075-709a1b0402cc

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-08-27

Date Updated: 2026-05-05

Author: Elizabeth Montalbano, Contributing Writer

...
...

Google's Threat Intelligence Group (GTIG) reported that UNC6395 abused OAuth tokens granted to the Salesloft Drift third-party app to systematically export sensitive data from multiple corporate Salesforce instances (observed Aug 8–18), harvesting AWS keys, passwords, and Snowflake tokens; Salesloft and Salesforce revoked tokens and removed the Drift app while GTIG and Mandiant published IoCs and remediation guidance urging organizations to search for exposed secrets, rotate credentials, and review Salesforce logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.