logo

The Ongoing Fallout from a Breach at AI Chatbot Maker Salesloft

ID: 42f6aaa4-e9ee-55d2-8c6e-5169ec4e95d9

STIX ID: report--42f6aaa4-e9ee-55d2-8c6e-5169ec4e95d9

Feed Name: Krebs on Security

Threat Score
78/100

Date Published: 2025-09-01

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

Salesloft’s Drift integration suffered a theft of authentication tokens that enabled attackers (identified by Google as UNC6395) to siphon data from multiple corporate Salesforce instances between Aug 8–18, 2025 and to access a limited number of Google Workspace accounts; stolen tokens span many third-party services (Slack, AWS S3, Azure, OpenAI, etc.), creating high risk of further compromise and lateral pivoting. Google and Salesloft advise immediate invalidation of all Salesloft-related tokens; Salesloft engaged Mandiant to investigate. Attribution remains uncertain but the incident is linked contextually to voice-phishing social-engineering campaigns and criminal groups claiming responsibility on Telegram.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.