1 of 1
Story summary
- Hackers accessed Salesloft's systems via a compromised GitHub account, stealing OAuth tokens from about 700 organizations.
- The breach occurred between August 8 and 18, allowing access to sensitive data, including AWS keys.
- Salesloft temporarily disabled its Drift application for security enhancements and has restored Salesforce integration.
- Mandiant's investigation identified attackers as UNC6395, who conducted thorough reconnaissance before the breach.
- Experts stress the importance of securing non-human identities, like API tokens, to avert future breaches.
