Loading cryptocurrency prices...

Salesloft Drift Supply Chain Attack Hits 700+ Firms, Data Stolen

Salesloft Takes Drift Chatbot Offline After Major Supply Chain Cyberattack Exposes Over 700 Organizations

  • Salesloft is temporarily taking its Drift chatbot service offline after a supply chain attack affected many companies.
  • The attack resulted in widespread theft of authentication tokens, impacting customer security and system integrity.
  • Google Threat Intelligence Group and Mandiant said the breach targeted Salesforce customer instances through compromised OAuth tokens from Drift.
  • More than 700 organizations may have been exposed to the cyberattack, according to Google.
  • Salesforce has temporarily disabled all Salesloft integrations as a safety measure, and the investigation is ongoing.

Salesloft announced on Tuesday that it will take the Drift chatbot service offline shortly after discovering a large-scale supply chain attack. Multiple organizations were affected, as attackers stole authentication tokens, threatening both company systems and customer data.

- Advertisement -

The company said this shutdown is the fastest way to review the application and improve security before restoring full service. In the meantime, the Drift chatbot will be unavailable on customer websites, and users will not have access to Drift. Salesloft stated it is working with Cybersecurity firms, including Mandiant and Coalition, to investigate and address the breach.

Recent findings by Google Threat Intelligence Group (GTIG) and Mandiant revealed that starting on August 8, 2025, a threat group used stolen OAuth and refresh tokens from Drift’s AI chat agent to access and compromise Salesforce customer accounts. OAuth tokens let applications access user account information without sharing passwords, making them a valuable target for attackers. The group, called UNC6395 (also known as GRUB1), may have affected more than 700 organizations, according to Google.

While the attack was first believed to only involve Salesloft’s integration with Salesforce, officials now warn that any platform connected to Drift may be at risk. The method used to first access the Drift application remains unclear. Salesforce responded by disabling all Salesloft integrations as a precaution.

Some impacted businesses have publicly confirmed the breach. “We believe this incident was not an isolated event but that the threat actor intended to harvest credentials and customer information for future attacks,” said Cloudflare. The company added, “Given that hundreds of organizations were affected through this Drift compromise, we suspect the threat actor will use this information to launch targeted attacks against customers across the affected organizations.”

- Advertisement -

Further investigation is underway as affected companies work to secure their systems and prevent additional incidents. The full extent of affected data is still being determined, and updates will follow as more information is released. For additional details, readers can refer to the official Salesloft advisory.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

IBM Unveils 120-Qubit Nighthawk Chip, Aiming for Quantum Advantage by 2026

IBM unveiled the Nighthawk and Quantum Loon quantum processors, marking significant progress toward verified...

Nvidia Eyes $200 Return Amid AI Growth and Strategic Deals

NVIDIA stock has encountered resistance near $200 but rose 5% over the last month...

JPMorgan Expands JPM Coin to Base, Eyes Retail and Multi-Currency Use

JPMorgan has launched its dollar-backed stablecoin, JPM Coin (JPMD), for institutional transfers on the...

Report: 16 Blockchains Have Built-in Fund Freezing Mechanisms

Sixteen blockchains have built-in fund freezing features, while 19 more can add this with...

Peraire-Bueno Bros Face Retrial in $25M Ethereum Fraud Case

Anton and James Peraire-Bueno face a potential retrial for alleged fraud and money laundering...
- Advertisement -

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...