spot_img
HomeNews & Current EventsSalesloft OAuth Tokens Compromised via Drift AI Chat Agent,...

Salesloft OAuth Tokens Compromised via Drift AI Chat Agent, Exposing Salesforce Customer Data

TLDR: A sophisticated data theft campaign, active from August 8 to August 18, 2025, saw threat actors compromise OAuth tokens linked to the Salesloft Drift AI chat agent. This breach allowed unauthorized access to numerous Salesforce customer instances, leading to the exfiltration of sensitive data including customer records, user information, and potentially critical credentials like AWS access keys and Snowflake tokens. Salesloft and Salesforce have responded by revoking tokens, removing the Drift application, and notifying affected customers.

A significant data breach impacting Salesforce customer data has been uncovered, stemming from the compromise of OAuth and refresh tokens associated with the Salesloft Drift artificial intelligence (AI) chat agent. The widespread data theft campaign, attributed to a threat actor tracked as UNC6395 by Google Threat Intelligence Group and Mandiant, was active from as early as August 8, 2025, through at least August 18, 2025.

Salesloft, a revenue orchestration platform, issued an advisory on August 20, 2025, confirming a security issue within the Drift application. The company stated that it proactively revoked connections between Drift and Salesforce and clarified that customers not utilizing the Drift-Salesforce integration were unaffected.

The attackers leveraged the compromised OAuth credentials to exfiltrate data from affected Salesforce instances. Salesloft reported that the threat actor executed queries to retrieve information associated with various Salesforce objects, including Cases, Accounts, Users, and Opportunities. Cybersecurity researchers further noted that the actors were observed exporting large volumes of data, likely with the aim of harvesting sensitive credentials such as Amazon Web Services (AWS) access keys (AKIA), passwords, and Snowflake-related access tokens.

Google Threat Intelligence Group and Mandiant highlighted that UNC6395 demonstrated operational security awareness by deleting query jobs after data exfiltration. The exact scale of the activity is not fully known, but Salesloft has confirmed it notified all affected parties. Salesforce, in a statement, acknowledged that a ‘small number of customers’ were impacted, emphasizing that the issue originated from a ‘compromise of the app’s connection’ rather than a vulnerability within the core Salesforce platform.

In response to the incident, Salesloft, in collaboration with Salesforce, swiftly invalidated all active Access and Refresh Tokens linked to the Drift application on August 20, 2025. Additionally, Salesforce removed the Drift application from its AppExchange until further investigation is complete. Administrators of affected organizations have been advised to re-authenticate their Salesforce connections to re-enable the integration and to review relevant logs for any potential evidence of data exposure. Google has also recommended immediate measures such as revoking API keys and rotating credentials.

Also Read:

This incident underscores the growing risk associated with third-party integrations and the sophisticated tactics employed by financially motivated threat groups targeting cloud-based platforms like Salesforce.

Tanya Menon
Tanya Menonhttps://blogs.edgentiq.com
Tanya Menon is a real-time news specialist focusing on fast updates and micro-analysis of the global AI market. Known for her agile and energetic reporting style, Tanya leverages automation tools to scan emerging news signals and deliver concise, actionable updates. Her coverage is essential for decision-makers who need the GenAI headlines before they go mainstream. You can reach her out at: [email protected]

- Advertisement -

spot_img

Gen AI News and Updates

spot_img

- Advertisement -