Drooid Logo
Back to story perspectives

Full Breakdown

Salesloft Drift Breach: A Supply Chain Attack Exposing Vulnerabilities

9/9/2025, 11:16:18 AM

Overview of the Incident

In a significant cybersecurity breach, Salesloft has confirmed that the compromise of its GitHub account between March and June 2025 led to a widespread data theft involving its Drift application. The attack, attributed to the threat group UNC6395, allowed hackers to access sensitive OAuth tokens, which were subsequently used to infiltrate Salesforce instances of numerous organizations, including major tech firms like Google, Cloudflare, and Palo Alto Networks.

Timeline of Events

  • March - June 2025: Attackers accessed Salesloft's GitHub account, downloading content from multiple repositories and establishing unauthorized workflows.
  • August 8 - 18, 2025: The main data theft campaign occurred, utilizing stolen OAuth tokens to access Salesforce data across various organizations.
  • September 5, 2025: Salesloft took the Drift application offline as a precautionary measure, while Salesforce temporarily suspended its integration with Drift.

Key Findings from the Investigation

The investigation led by Google-owned Mandiant revealed that the attackers conducted reconnaissance activities within the Salesloft and Drift environments before launching the data theft. They accessed Drift's Amazon Web Services (AWS) environment, where they obtained OAuth tokens that allowed them to breach customer Salesforce instances. The compromised data primarily included business contact information and sensitive credentials, such as AWS access keys and passwords.

Impact on Affected Organizations

Salesloft's breach has affected at least 22 companies, with many reporting unauthorized access to customer data stored in their Salesforce instances. Notable victims include:

  • Cloudflare
  • Bugcrowd

These organizations have since taken steps to mitigate the risks, including revoking compromised credentials and disabling the Drift application.

Official Statements & Responses

Criticism & Opposition

Security analysts have raised concerns about Salesloft's security posture, particularly regarding the six-month delay in detecting the initial GitHub breach. Experts have called for improved monitoring and stricter access controls for third-party applications, highlighting the need for organizations to protect non-human identities, such as API tokens.

Conflicting Reports & Gaps

While Salesloft has confirmed the breach's containment, there are discrepancies regarding the total number of affected organizations and the extent of the data stolen. Estimates suggest that around 700 companies may have been impacted, but the exact scope remains unclear.

What's Next

As investigations continue, regulatory scrutiny is expected to increase, potentially leading to new guidelines for SaaS security. Organizations are urged to conduct regular audits of their code repositories and implement zero-trust architectures to mitigate future risks.

Verbatim Quotes

  • “The threat actor used the stolen OAuth tokens to access data via Drift integrations.” — Salesloft
  • “This incident highlights a significant systemic blind spot in how organizations manage ‘Non-Human Identities’ like API tokens, which are used for communication between platforms,” — Rom Carmel, CEO of Apono
  • “Security experts warn that the incident underscores growing risks in cloud-first environments where third-party integrations can become powerful attack vectors, urging organisations to immediately audit OAuth permissions and implement stricter access controls for third-party applications.” — Cybersecurity Analyst

This incident serves as a critical reminder of the vulnerabilities inherent in interconnected software ecosystems and the need for robust security measures to protect sensitive data.