Threat Brief: Salesloft Drift Integration Used To Compromise Salesforce Instances
ID: dfd1a3d1-2161-5ada-8f77-50901e4c240e
STIX ID: report--dfd1a3d1-2161-5ada-8f77-50901e4c240e
Feed Name: Palo Alto Networks Unit 42
Unit 42 observed a campaign (Aug 8–18, 2025) where a threat actor leveraged compromised OAuth credentials for the Salesloft Drift integration to mass-exfiltrate Salesforce records (Account, Contact, Case, Opportunity), scanned stolen data for credentials, and deleted SOQL queries to hide activity; Salesloft revoked tokens, notified customers, and guidance includes log review, credential rotation, and hunting for IoCs such as the Python/3.11 aiohttp/3.12.15 user agent and known malicious IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
