logo

Salesloft Drift Breach: What Happened and How Does It Affect Me? | UpGuard

ID: 056eae1a-3191-51ab-93ad-ccb8071c08f8

STIX ID: report--056eae1a-3191-51ab-93ad-ccb8071c08f8

Feed Name: UpGuard Blog

Threat Score
90/100

Date Published: 2025-09-09

Date Updated: 2026-05-01

...
...

A Mandiant-validated investigation into a 2025 Salesloft/Drift supply-chain compromise found an attacker accessed Salesloft GitHub repos, added persistent access, pivoted into the Drift application AWS environment, stole OAuth tokens for Drift integrations, and used those tokens to access and exfiltrate data from many organizations' Salesforce instances; the Drift environment was contained, credentials rotated, the Salesforce integration restored after reconciliation, and UpGuard published detection guidance, IOCs, and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.