Google Warns of Widespread Data Breach Impacting Salesforce Users

Google Reports Widespread Attack Targeting Salesforce Accounts via Salesloft Drift Integration, Urges Immediate Security Actions

  • Google disclosed a broad attack affecting Salesforce instances through Salesloft Drift integrations.
  • All authentication tokens connected to Drift are considered potentially compromised, according to Google’s advisory.
  • Attackers used stolen OAuth tokens to access some Google Workspace email accounts connected to Drift.
  • Google revoked affected tokens and disabled integrations, urging organizations to review and secure third-party connections.
  • Salesloft said there is no evidence Salesloft integrations themselves were compromised, but all Salesloft integrations with Salesforce are temporarily disabled.

Google reported that attackers have targeted Salesforce accounts using the Salesloft Drift integration, affecting all related integrations as of August 2025. The company identified this as a widespread security incident and alerted affected users.

- Advertisement -

The breach allowed attackers to obtain OAuth tokens—digital “keys” that help applications access data without sharing passwords—from Drift’s platform. These stolen tokens were then used to access a small number of Google Workspace email accounts on August 9, 2025. According to an advisory from Google’s Threat Intelligence Group and Mandiant, the issue did not compromise Google Workspace or Alphabet systems directly.

Google said, “We now advise all Salesloft Drift customers to treat any and all authentication tokens stored in or connected to the Drift platform as potentially compromised.” The company notified those affected, revoked the specific Drift Email OAuth tokens, and suspended integration features between Google Workspace and Salesloft Drift pending further investigation.

In a further step, Google called for all organizations using Salesloft Drift to check third-party integrations, revoke and update credentials, and look for signs of unauthorized activity across their systems. The company linked the attacks to the threat group “UNC6395,” which it said had targeted Salesforce accounts using compromised tokens from August 8 to 18, 2025, as described in their updated advisory.

Salesloft posted updates about the incident, noting that Salesforce temporarily disabled the Drift integration with Salesforce, Slack, and Pardot, eventually deciding to suspend all Salesloft integrations with Salesforce for safety. Salesloft stated, “Based on the investigation to date, there is no evidence of malicious activity detected in the Salesloft integrations related to the Drift incident. Additionally, at this time, there are no indications that the Salesloft integrations are compromised or at risk.” You can find full statements in their initial update and follow-up notice.

- Advertisement -

Google recommends organizations take immediate action to secure credentials, audit integrations, and monitor for suspicious access across platforms. Salesforce has additional guidance available on its status page.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Jeffy Yu, Crypto Founder Who Faked Death, Allegedly Dies

Crypto founder Jeffy Yu is alleged to have committed suicide in Roseville on New...

Unstable Ground: Looming U.S. Crypto Rules May Lack Legal Backing

SEC Chairman Paul Atkins is pushing for crypto rules but warns they need a...

Apple Stock Forms Technical Buy Point, Nears Breakout

Apple stock (AAPL) is forming a technical buy point and nearing a breakout, with...

LSEG to launch Digital Securities Sandbox for tokenization

London Stock Exchange Group (LSEG) plans to launch a Digital Securities Sandbox (DSD) this...

Tesla China Sales Slide in Jan., Exports Jump 71%

Tesla's retail sales in China plunged to 18,485 vehicles in January, their lowest monthly...

Must Read

9 Best Trading Platforms for Crypto Beginners

Many newcomers to the crypto space are looking for platforms to buy, sell and exchange cryptocurrencies. While there are hundreds of crypto exchanges around...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!