BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Google Warns of Widespread Data Breach Impacting Salesforce Users

Google Reports Widespread Attack Targeting Salesforce Accounts via Salesloft Drift Integration, Urges Immediate Security Actions

  • Google disclosed a broad attack affecting Salesforce instances through Salesloft Drift integrations.
  • All authentication tokens connected to Drift are considered potentially compromised, according to Google’s advisory.
  • Attackers used stolen OAuth tokens to access some Google Workspace email accounts connected to Drift.
  • Google revoked affected tokens and disabled integrations, urging organizations to review and secure third-party connections.
  • Salesloft said there is no evidence Salesloft integrations themselves were compromised, but all Salesloft integrations with Salesforce are temporarily disabled.

Google reported that attackers have targeted Salesforce accounts using the Salesloft Drift integration, affecting all related integrations as of August 2025. The company identified this as a widespread security incident and alerted affected users.

- Advertisement -

The breach allowed attackers to obtain OAuth tokens—digital “keys” that help applications access data without sharing passwords—from Drift’s platform. These stolen tokens were then used to access a small number of Google Workspace email accounts on August 9, 2025. According to an advisory from Google’s Threat Intelligence Group and Mandiant, the issue did not compromise Google Workspace or Alphabet systems directly.

Google said, “We now advise all Salesloft Drift customers to treat any and all authentication tokens stored in or connected to the Drift platform as potentially compromised.” The company notified those affected, revoked the specific Drift Email OAuth tokens, and suspended integration features between Google Workspace and Salesloft Drift pending further investigation.

In a further step, Google called for all organizations using Salesloft Drift to check third-party integrations, revoke and update credentials, and look for signs of unauthorized activity across their systems. The company linked the attacks to the threat group “UNC6395,” which it said had targeted Salesforce accounts using compromised tokens from August 8 to 18, 2025, as described in their updated advisory.

Salesloft posted updates about the incident, noting that Salesforce temporarily disabled the Drift integration with Salesforce, Slack, and Pardot, eventually deciding to suspend all Salesloft integrations with Salesforce for safety. Salesloft stated, “Based on the investigation to date, there is no evidence of malicious activity detected in the Salesloft integrations related to the Drift incident. Additionally, at this time, there are no indications that the Salesloft integrations are compromised or at risk.” You can find full statements in their initial update and follow-up notice.

- Advertisement -

Google recommends organizations take immediate action to secure credentials, audit integrations, and monitor for suspicious access across platforms. Salesforce has additional guidance available on its status page.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Baron Bets $1B on SpaceX IPO for “Largest Company”

Veteran investor Ron Baron revealed plans for a $1 billion SpaceX IPO investment and...

Senate Forces Vote on Iran War Authorization

The U.S. Senate has voted to advance a resolution requiring President Trump to seek...

GitHub Probes Internal Repo Theft

GitHub is investigating unauthorized access to its internal repositories after a threat actor listed...

SOL’s Negative Funding Rate Hints at Bearish Pressure

Solana's SOL token corrected 15% after facing rejection at $98, with derivatives data showing...

Prometheum Executes First Crypto Trades After 10-Year Wait

Prometheum has executed its first crypto trades nearly a decade after its founding and...

Must Read

Top 9 VPNs That Accept Bitcoin And Crypto

CyberGhost | FastVPN | TorGuard | Private Internet Access | ExpressVPN | NordVPN | Private VPN | SurfShark | AirVPN | Why Buy VPN...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading