Widespread Data Theft Targets Salesforce Instances via Salesloft Drift
ID: a1f78887-29ac-58a0-b727-56e4ef5914ca
STIX ID: report--a1f78887-29ac-58a0-b727-56e4ef5914ca
Feed Name: Threat Intelligence
Threat Score
GTIG reports a widespread data theft campaign (Aug 8–18, 2025) by UNC6395 that used compromised Salesloft/Drift OAuth tokens to systematically export large volumes of data from multiple corporate Salesforce instances and search for sensitive credentials—including AWS access keys and Snowflake tokens; Salesloft and Salesforce revoked affected tokens, removed the Drift application from AppExchange, and notified impacted organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
