TLDR: A sophisticated data theft campaign, active from August 8 to August 18, 2025, saw threat actors compromise OAuth tokens linked to the Salesloft Drift AI chat agent. This breach allowed unauthorized access to numerous Salesforce customer instances, leading to the exfiltration of sensitive data including customer records, user information, and potentially critical credentials like AWS access keys and Snowflake tokens. Salesloft and Salesforce have responded by revoking tokens, removing the Drift application, and notifying affected customers.
A significant data breach impacting Salesforce customer data has been uncovered, stemming from the compromise of OAuth and refresh tokens associated with the Salesloft Drift artificial intelligence (AI) chat agent. The widespread data theft campaign, attributed to a threat actor tracked as UNC6395 by Google Threat Intelligence Group and Mandiant, was active from as early as August 8, 2025, through at least August 18, 2025.
Salesloft, a revenue orchestration platform, issued an advisory on August 20, 2025, confirming a security issue within the Drift application. The company stated that it proactively revoked connections between Drift and Salesforce and clarified that customers not utilizing the Drift-Salesforce integration were unaffected.
The attackers leveraged the compromised OAuth credentials to exfiltrate data from affected Salesforce instances. Salesloft reported that the threat actor executed queries to retrieve information associated with various Salesforce objects, including Cases, Accounts, Users, and Opportunities. Cybersecurity researchers further noted that the actors were observed exporting large volumes of data, likely with the aim of harvesting sensitive credentials such as Amazon Web Services (AWS) access keys (AKIA), passwords, and Snowflake-related access tokens.
Google Threat Intelligence Group and Mandiant highlighted that UNC6395 demonstrated operational security awareness by deleting query jobs after data exfiltration. The exact scale of the activity is not fully known, but Salesloft has confirmed it notified all affected parties. Salesforce, in a statement, acknowledged that a ‘small number of customers’ were impacted, emphasizing that the issue originated from a ‘compromise of the app’s connection’ rather than a vulnerability within the core Salesforce platform.
In response to the incident, Salesloft, in collaboration with Salesforce, swiftly invalidated all active Access and Refresh Tokens linked to the Drift application on August 20, 2025. Additionally, Salesforce removed the Drift application from its AppExchange until further investigation is complete. Administrators of affected organizations have been advised to re-authenticate their Salesforce connections to re-enable the integration and to review relevant logs for any potential evidence of data exposure. Google has also recommended immediate measures such as revoking API keys and rotating credentials.
Also Read:
- AI Summarization Tools Exploited as New Malware Delivery Vector
- Okta Bolsters Privileged Access Management with Axiom Security Acquisition Amidst AI Expansion
This incident underscores the growing risk associated with third-party integrations and the sophisticated tactics employed by financially motivated threat groups targeting cloud-based platforms like Salesforce.


