BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Hackers Breach Salesloft via Drift App to Steal Salesforce Data

Hackers Exploit OAuth Tokens in Salesloft and Drift Integration to Breach Salesforce Customer Data

  • Hackers breached Salesloft and used compromised OAuth tokens to access Salesforce customer data.
  • The threat group, identified as UNC6395, targeted Salesforce instances linked to the Drift AI chat app between August 8 and August 18, 2025.
  • Attackers exported sensitive data, including Amazon Web Services (AWS) keys, passwords, and other credentials.
  • Salesloft and Salesforce stated that they revoked affected tokens and removed Drift from AppExchange to stop the breach.
  • Security experts warn this campaign could be part of a larger supply chain attack, affecting service providers and their customers.

A data theft campaign has impacted the sales automation platform Salesloft, allowing Hackers to use stolen access tokens to break into customer accounts on Salesforce, according to findings from Google Threat Intelligence Group and Mandiant. The attacks began as early as August 8, 2025, and continued through at least August 18, with the focus on exploiting OAuth and refresh tokens tied to the third-party Drift AI chat integration.

- Advertisement -

Researchers report that the threat actor, tracked as UNC6395, used the breach to pull large amounts of data from several companies’ Salesforce systems. According to Salesloft, the attacker ran database queries in Salesforce to gather information such as customer cases, accounts, users, and opportunities. Exfiltrated credentials also include AWS keys, passwords, and tokens related to the data cloud company Snowflake.

In its advisory, Salesloft confirmed, “A threat actor used OAuth credentials to exfiltrate data from our customers’ Salesforce instances.” The company has revoked the connection between Drift and Salesforce and recommends administrators re-authenticate Salesforce connections to restore integration. Salesforce said only a small number of customers were affected by the compromised app connection and that both companies worked quickly to invalidate all active access and refresh tokens. As part of its response, Salesforce also removed the Drift app from its AppExchange and alerted those impacted. Official statements and ongoing updates are available in both Salesloft’s advisory and the Salesforce status page.

Security investigators note that UNC6395 showed deliberate efforts to cover its tracks, for example by deleting activity logs. Google recommends that organizations review system records for signs of data exposure, switch out all credentials and API keys, and conduct a full investigation of their systems.

Industry experts say that this attack may be the first stage of a larger supply chain threat. Cory Michal, Chief Security Officer of AppOmni, states that many affected targets were technology and security providers themselves, warning, “This wasn’t a one-off compromise; hundreds of Salesforce tenants of specific organizations of interest were targeted using stolen OAuth tokens, and the attacker methodically queried and exported data across many environments.”

- Advertisement -

Recent months have seen other financially motivated groups, such as UNC6040 (also known as ShinyHunters) and UNC6240, join forces to target Salesforce environments. Many organizations remain on alert for further activity as the investigation continues.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Dips to $66k Despite Stock Market Gains

Bitcoin cooled its recent rebound on Tuesday, dropping to around $66,000 as the stock...

New Android Rokarolla Trojan Targets 217 Banking Apps

A new Android banking trojan named Rokarolla targets 217 banking and cryptocurrency applications.It uses...

3 Cryptocurrencies Near All-Time Highs As Market Recovers

Bitcoin recovered to $67,000 on June 15, 2026, following a dip below $60,000.Hyperliquid (HYPE)...

Hype ETFs Near $172M Inflows Defying Bitcoin ETF Exodus

Cumulative inflows for three new Hyperliquid ETFs reached nearly $172 million in roughly a...

Robinhood Lays Off 10% Staff Amid Record Trading

Robinhood Markets is cutting 10% of its full-time staff in a "proactive operational move"...

Must Read

7 Best Audiobooks on Cybersecurity

Cybersecurity has become an essential topic in our increasingly digital world. As technology evolves and becomes more integrated into our daily lives, the importance...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading