logo

Threat Brief: Salesloft Drift Integration Used To Compromise Salesforce Instances

ID: dfd1a3d1-2161-5ada-8f77-50901e4c240e

STIX ID: report--dfd1a3d1-2161-5ada-8f77-50901e4c240e

Feed Name: Palo Alto Networks Unit 42

Threat Score
75/100

Date Published: 2025-09-02

Date Updated: 2026-04-28

Author: Unit 42

...
...

Unit 42 observed a campaign (Aug 8–18, 2025) where a threat actor leveraged compromised OAuth credentials for the Salesloft Drift integration to mass-exfiltrate Salesforce records (Account, Contact, Case, Opportunity), scanned stolen data for credentials, and deleted SOQL queries to hide activity; Salesloft revoked tokens, notified customers, and guidance includes log review, credential rotation, and hunting for IoCs such as the Python/3.11 aiohttp/3.12.15 user agent and known malicious IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.