Google Warns of Widespread Data Breach Impacting Salesforce Users

Google Reports Widespread Attack Targeting Salesforce Accounts via Salesloft Drift Integration, Urges Immediate Security Actions

  • Google disclosed a broad attack affecting Salesforce instances through Salesloft Drift integrations.
  • All authentication tokens connected to Drift are considered potentially compromised, according to Google’s advisory.
  • Attackers used stolen OAuth tokens to access some Google Workspace email accounts connected to Drift.
  • Google revoked affected tokens and disabled integrations, urging organizations to review and secure third-party connections.
  • Salesloft said there is no evidence Salesloft integrations themselves were compromised, but all Salesloft integrations with Salesforce are temporarily disabled.

Google reported that attackers have targeted Salesforce accounts using the Salesloft Drift integration, affecting all related integrations as of August 2025. The company identified this as a widespread security incident and alerted affected users.

- Advertisement -

The breach allowed attackers to obtain OAuth tokens—digital “keys” that help applications access data without sharing passwords—from Drift’s platform. These stolen tokens were then used to access a small number of Google Workspace email accounts on August 9, 2025. According to an advisory from Google’s Threat Intelligence Group and Mandiant, the issue did not compromise Google Workspace or Alphabet systems directly.

Google said, “We now advise all Salesloft Drift customers to treat any and all authentication tokens stored in or connected to the Drift platform as potentially compromised.” The company notified those affected, revoked the specific Drift Email OAuth tokens, and suspended integration features between Google Workspace and Salesloft Drift pending further investigation.

In a further step, Google called for all organizations using Salesloft Drift to check third-party integrations, revoke and update credentials, and look for signs of unauthorized activity across their systems. The company linked the attacks to the threat group “UNC6395,” which it said had targeted Salesforce accounts using compromised tokens from August 8 to 18, 2025, as described in their updated advisory.

Salesloft posted updates about the incident, noting that Salesforce temporarily disabled the Drift integration with Salesforce, Slack, and Pardot, eventually deciding to suspend all Salesloft integrations with Salesforce for safety. Salesloft stated, “Based on the investigation to date, there is no evidence of malicious activity detected in the Salesloft integrations related to the Drift incident. Additionally, at this time, there are no indications that the Salesloft integrations are compromised or at risk.” You can find full statements in their initial update and follow-up notice.

- Advertisement -

Google recommends organizations take immediate action to secure credentials, audit integrations, and monitor for suspicious access across platforms. Salesforce has additional guidance available on its status page.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Telcos Join Theta Network as Validators, Boosting Trust Now!

Deutsche Telekom and NTT Digital have joined a blockchain network as enterprise validators.Telecom operators...

Gold Surge Tops $34T; Bitcoin Falters Amid Fed Pick Buzz Now

Gold’s market value has surged to about $34 trillion, outpacing Bitcoin’s recent gains.BlackRock holds...

UBS to Offer Bitcoin and Ethereum Trading for Swiss Clients.

UBS Group AG will allow select private banking clients in Switzerland to trade Bitcoin...

Optimism DAO split over proposal to fund monthly OP buybacks

Delegates in the Optimism DAO are voting on a plan to use 50% of...

FBI Links $1B USDT Laundering to Jorge Figueira Scheme Probe

Jorge Figueira is charged in a U.S. money‑laundering case tied to over $1 billion...
- Advertisement -

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!