BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Salesloft Drift Supply Chain Attack Hits 700+ Firms, Data Stolen

Salesloft Takes Drift Chatbot Offline After Major Supply Chain Cyberattack Exposes Over 700 Organizations

  • Salesloft is temporarily taking its Drift chatbot service offline after a supply chain attack affected many companies.
  • The attack resulted in widespread theft of authentication tokens, impacting customer security and system integrity.
  • Google Threat Intelligence Group and Mandiant said the breach targeted Salesforce customer instances through compromised OAuth tokens from Drift.
  • More than 700 organizations may have been exposed to the cyberattack, according to Google.
  • Salesforce has temporarily disabled all Salesloft integrations as a safety measure, and the investigation is ongoing.

Salesloft announced on Tuesday that it will take the Drift chatbot service offline shortly after discovering a large-scale supply chain attack. Multiple organizations were affected, as attackers stole authentication tokens, threatening both company systems and customer data.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

The company said this shutdown is the fastest way to review the application and improve security before restoring full service. In the meantime, the Drift chatbot will be unavailable on customer websites, and users will not have access to Drift. Salesloft stated it is working with Cybersecurity firms, including Mandiant and Coalition, to investigate and address the breach.

Recent findings by Google Threat Intelligence Group (GTIG) and Mandiant revealed that starting on August 8, 2025, a threat group used stolen OAuth and refresh tokens from Drift’s AI chat agent to access and compromise Salesforce customer accounts. OAuth tokens let applications access user account information without sharing passwords, making them a valuable target for attackers. The group, called UNC6395 (also known as GRUB1), may have affected more than 700 organizations, according to Google.

While the attack was first believed to only involve Salesloft’s integration with Salesforce, officials now warn that any platform connected to Drift may be at risk. The method used to first access the Drift application remains unclear. Salesforce responded by disabling all Salesloft integrations as a precaution.

Some impacted businesses have publicly confirmed the breach. “We believe this incident was not an isolated event but that the threat actor intended to harvest credentials and customer information for future attacks,” said Cloudflare. The company added, “Given that hundreds of organizations were affected through this Drift compromise, we suspect the threat actor will use this information to launch targeted attacks against customers across the affected organizations.”

- Advertisement -

Further investigation is underway as affected companies work to secure their systems and prevent additional incidents. The full extent of affected data is still being determined, and updates will follow as more information is released. For additional details, readers can refer to the official Salesloft advisory.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ethereum Aims for Quantum Resistance by 2029

The Ethereum Foundation has launched a "Post-Quantum Ethereum" resource hub to address future quantum...

NASA Shifts Artemis to Build $20B Permanent Moon Base

NASA has shifted its Artemis program strategy, now prioritizing the construction of a permanent...

War Sparks Cash Rush, Gold & Bonds Dumped

Bitcoin is under pressure as investors flee to cash, with Bitcoin retesting $67,500 support...

Circle Shares Plummet 20%; Tether Audit, Yield Bill Weigh

Circle's stock (CRCL) plummeted 20% on Tuesday, erasing recent gains.Rival Tether announced a major...

Robinhood announces $1.5B buyback plan over three years

Robinhood announced a new share repurchase program for up to $1.5 billion.The firm's shares...

Must Read

Are Cryptocurrency Securities?

TL;DR - Cryptocurrencies are not typically considered securities, as they are decentralized digital assets that operate independently of any central authority or government. However,...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading