The Salesloft Drift incident was a third-party SaaS and OAuth-token compromise, not a demonstrated vulnerability in Salesforce’s core platform. Attackers obtained credentials associated with Drift customer integrations, used the trusted application identity to query Salesforce organizations, exported data, and searched it for credentials that could enable further access. Google Threat Intelligence tracked the activity as UNC6395; the principal Salesforce campaign ran from August 8 through at least August 18, 2025.
The practical lesson is stark: every integration is an identity, a permission set, and a data-flow path. Govern it like a privileged service account rather than harmless plumbing.
The incident in one view
- What was compromised: OAuth credentials associated with customer integrations.
- Observed activity: Systematic queries of Salesforce objects including Account, Case, Opportunity, and User, followed by bulk export and searching for AWS keys, passwords, and Snowflake-related tokens.
- Who tracked it: Google Threat Intelligence as UNC6395.
- What it was not: Salesforce has said the incident did not stem from a vulnerability in the core Salesforce platform.
An OAuth access or refresh token can function as a bearer credential. Possession may allow an attacker to act as the already-authorized application without repeating the original interactive password and MFA flow; the actual access still depends on token type, scope, lifetime, and provider controls.
What happened, and when
Two related stories must be kept separate: the earlier intrusion into Salesloft and Drift environments, and the later use of compromised integration tokens against customer tenants.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
| Date | Event |
|---|---|
| March–June 2025 | Salesloft’s later investigation identified reconnaissance and suspicious activity involving Salesloft, GitHub, and Drift environments, including secret enumeration. These findings describe the vendor investigation, not every customer’s exposure. |
| August 8–18, 2025 | Google identified the principal campaign querying and exfiltrating data from Salesforce organizations through Drift-associated OAuth tokens. |
| August 20, 2025 | Salesloft revoked active Drift access and refresh tokens; Google also reported Drift’s removal from Salesforce AppExchange at that stage. |
| August 26–28, 2025 | Salesforce and customers issued notifications. Salesforce disabled Drift’s connection and then all Salesloft integrations as a precaution. |
| August 28, 2025 | Google expanded its warning beyond Salesforce, advising Drift customers to treat tokens stored in or connected to Drift as potentially compromised. Drift Email tokens were also implicated. |
| September 7, 2025 | Salesforce re-enabled Salesloft integrations other than Drift. |
| April 17, 2026 | Salesloft reported continuing hardening, MFA changes, credential rotation, GitHub hardening, and log/configuration review. The latest cited update did not say that Drift had been restored. |
Sources: Google Threat Intelligence, Salesforce status, and Salesloft Trust Center.
Why a trusted integration became toxic
Authorization created a durable identity
Customers trusted Salesloft; Salesforce trusted the authorized Drift connected app; administrators trusted an approval that had already been granted. Once tokens were issued, API requests could look like normal application activity rather than a new, obviously malicious login.
Business data became a staging area
CRM records, cases, notes, and custom objects often contain copied credentials, configuration details, or links to other systems. Google reported searches for AWS access keys, passwords, and Snowflake tokens. Finding a secret is not proof it was successfully used, but it changes a CRM theft into a potential cloud-identity incident.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
One vendor can concentrate many customers
A shared application and centralized token handling create a supply-chain boundary. A single vendor-side compromise can expose many customer organizations even when each customer’s Salesforce core is configured securely.
Was Salesforce itself hacked?
Not according to the cited first-party descriptions. Salesforce said the issue did not result from a vulnerability in the core platform; customer data was accessed through compromised Drift connection credentials. That distinction does not eliminate Salesforce’s responsibilities: it still had to detect unusual activity, disable the connection, notify customers, and provide revocation and investigation guidance.
What data could have been exposed?
Exposure varied by organization, scopes, enabled features, and what customers stored in Salesforce. Plausible categories include:
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
- Records accessible to the Drift integration, including contacts and business information.
- Support cases and related data where the connected app had those permissions.
- Secrets embedded in records, notes, attachments, or custom objects.
- Tokens for other services that were stored in or reachable through Drift-related systems.
- A limited number of Google Workspace accounts configured specifically for Drift Email. Google said this was not an intrusion into Google Workspace or Alphabet itself.
Cloudflare’s public response illustrates why impact cannot be generalized: its investigation found access to Salesforce data and led to rotation of 104 API tokens, while that disclosure did not establish compromise of its underlying products and infrastructure through the same path. Do not convert individual victim disclosures into a universal impact claim.
How attackers operated inside Salesforce
Google observed systematic querying of objects such as Account, Case, Opportunity, and User, followed by bulk data export. These examples are illustrative, not a complete list of activity.
Free tools Windows power users keep installed
One-click scans. No signup required.
- Legitimate application origin can make requests blend into normal automation.
- Login history may not show the full query and export pattern.
- Valid tokens avoid the password-reset and new-consent signals many defenses expect.
- Query jobs or related artifacts may be deleted while retained event logs still record access.
- A familiar service identity can generate abnormal volume or enumerate objects it rarely touches.
Google’s defensive guidance notes that detailed connected-app, API, and export telemetry may require Salesforce Shield’s Event Monitoring or the Event Monitoring add-on: guidance on detecting SaaS abuse.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What an affected organization should do
First hour: contain without destroying evidence
- Disable or disconnect Drift and related Salesloft integrations.
- In Salesforce, open Setup → Connected Apps → OAuth Usage; identify Drift/Salesloft grants and revoke them. Salesforce documents the workflow at its incident guidance and describes API-based revocation in OAuth Usage documentation.
- Preserve Salesforce, identity-provider, cloud, email, repository, and SaaS logs before changing settings or deleting jobs.
- Notify legal, privacy, compliance, cyber-insurance, and incident-response contacts.
First day: determine what the token could reach
- Review connected-app usage, token history, authorization grants, and API activity.
- Look for high-volume queries or exports and access to Account, Case, Opportunity, User, and sensitive custom objects.
- Check source IPs, anonymizing-proxy or TOR indicators, impossible-travel patterns, and unexpected app changes.
- Search Salesforce data and exports for AWS keys, Snowflake tokens, passwords, API keys, and other secrets.
- Check downstream cloud audit logs for use of any exposed credentials.
- Review Google Workspace or other integration logs if Drift Email was enabled.
- Ask whether query jobs or operational artifacts were deleted; absence of those artifacts does not prove absence of access.
First week: eradicate and recover
- Rotate access tokens, refresh tokens, API keys, passwords, and cloud access keys—not merely the Salesforce password.
- Reissue credentials through a clean administrative process.
- Remove secrets from CRM fields, cases, notes, spreadsheets, tickets, chat transcripts, and code repositories; scan GitHub and similar systems for leaked environment variables.
- Separate production, development, support, build, and administrative planes.
- Require vendor evidence of remediation, independent validation, and a safe re-enablement plan before reconnecting.
Salesloft says its remediation included Drift isolation, credential rotation, GitHub hardening, MFA work, secret remediation, and Mandiant-validated technical segmentation. That validates described controls; it is not a guarantee of zero residual risk.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Controls that reduce the blast radius
| Control | Practical implementation | Trade-off |
|---|---|---|
| Least-privilege OAuth | Limit objects and actions to the workflow; split workflows across identities instead of granting one app universal access. | Some features may require redesign or additional integrations. |
| Dedicated integration identities | Never use broad administrator accounts for third-party apps; assign an owner and business purpose. | More identities require lifecycle management. |
| Short-lived credentials and rotation | Automate refresh-token and key rotation, with tested recovery. | Frequent rotation can interrupt poorly designed automations. |
| OAuth inventory and allowlisting | Track scopes, expiration, last use, criticality, and owner; block unreviewed connected apps. | Centralized security teams need cooperation from SaaS owners. |
| Secret hygiene | Prohibit cloud keys, passwords, and API tokens in CRM records, tickets, notes, and chat. | Migration and historical cleanup take time. |
| SaaS-native monitoring | Alert on new grants, bulk exports, unusual object enumeration, query spikes, and anomalous API behavior. | Detailed telemetry can cost more and create noise; Event Monitoring may require Shield licensing. |
| Vendor segmentation | Require separation of customer data, product environments, repositories, build systems, and administrative planes. | Validation depends on vendor evidence and independent testing. |
| Emergency offboarding | Maintain a customer-controlled, tested way to revoke an app without waiting for the vendor. | Fast disconnection can interrupt lead routing or support workflows; prepare manual fallbacks. |
| Contractual controls | Require rapid breach notice, forensic cooperation, audit rights, subprocessor disclosure, token-handling commitments, and evidence of testing. | Contracts improve leverage but do not replace runtime controls. |
Questions for security, procurement, and executives
- Which customer credentials and refresh tokens does the vendor store, and can it retrieve them?
- Can scopes be limited per tenant, workflow, and identity?
- How quickly can the vendor revoke every customer token, and can customers revoke access independently?
- Are customer data, repositories, build systems, and administrative environments technically segmented?
- What connected-app, API, export, and administrative logs are available, for how long, and at what license tier?
- Will the vendor provide forensic cooperation, evidence of remediation, and independent validation after an incident?
- What is the tested manual fallback if the integration must be disconnected immediately?
Tools and services that support the response
Start with native controls before buying additional software. Salesforce’s Shield can provide deeper event visibility where the edition and budget justify it; pricing and packaging are quote-based and should be confirmed with Salesforce. Every customer should use the connected-app review path documented in OAuth Usage.
Organizations without SaaS forensics may use a managed incident-response provider such as Mandiant Consulting or an insurer’s response panel such as Coalition Cyber Insurance. These services are generally quote-based and do not replace customer-side revocation or evidence preservation.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
Large estates may consider SaaS security posture and access-governance platforms such as AppOmni or SPIN.AI. Evaluate OAuth inventory, scope analysis, dormant-token detection, export anomaly detection, automated revocation, SIEM/SOAR integration, evidence retention, and coverage across Salesforce, Google Workspace, Microsoft 365, Slack, and GitHub. No cited vendor should be assumed to have detected or prevented this incident unless it publicly documents that fact.
The durable lesson
The answer is not to reject SaaS, AI assistants, or integrations. It is to stop treating them as invisible plumbing. A connected application is a service identity with permissions, secrets, logs, and a supply-chain boundary. Inventory it, minimize its scopes, monitor its behavior, keep secrets out of business records, and rehearse rapid revocation. That is how a trusted relationship remains useful without becoming a single point of failure.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




