logo

Widespread Data Theft Targets Salesforce Instances via Salesloft Drift

ID: a1f78887-29ac-58a0-b727-56e4ef5914ca

STIX ID: report--a1f78887-29ac-58a0-b727-56e4ef5914ca

Feed Name: Threat Intelligence

Threat Score
78/100

Date Published: 2025-08-26

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

GTIG reports a widespread data theft campaign (Aug 8–18, 2025) by UNC6395 that used compromised Salesloft/Drift OAuth tokens to systematically export large volumes of data from multiple corporate Salesforce instances and search for sensitive credentials—including AWS access keys and Snowflake tokens; Salesloft and Salesforce revoked affected tokens, removed the Drift application from AppExchange, and notified impacted organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.