Drooid Logo
Back to today’s briefing

Story perspectives

Salesloft Breach Exposes Data of 700 Organizations

9/9/2025

24 5 Full Breakdown

1 of 1

Story summary
  • Hackers accessed Salesloft's systems via a compromised GitHub account, stealing OAuth tokens from about 700 organizations.
  • The breach occurred between August 8 and 18, allowing access to sensitive data, including AWS keys.
  • Salesloft temporarily disabled its Drift application for security enhancements and has restored Salesforce integration.
  • Mandiant's investigation identified attackers as UNC6395, who conducted thorough reconnaissance before the breach.
  • Experts stress the importance of securing non-human identities, like API tokens, to avert future breaches.