DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
World desk7 min

Salesloft Drift Breach: What Happened and What SaaS Teams Should Do

The Salesloft Drift incident abused stolen OAuth credentials to reach some customer Salesforce environments and connected SaaS accounts. Here is the timeline, attack chain, exposure assessment and response checklist.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: The 2025 Salesloft Drift incident was a third-party SaaS and OAuth-token compromise, not evidence that Salesforce’s core platform was hacked. Attackers obtained credentials linked to Salesloft’s Drift environment and replayed trusted application tokens to access some customer Salesforce organizations and other connected services.

The main Salesforce access window reported by Salesloft was August 8–18, 2025. Salesforce disabled the Drift connection on August 28. Exposure depended on whether an organization used an affected integration, the permissions it granted, and the data stored in its connected systems.

The incident in one diagram

Salesloft/Drift systems compromised → OAuth and refresh tokens obtained → attacker impersonates the approved Drift application → customer Salesforce and selected connected SaaS systems queried → records and potentially embedded secrets exfiltrated.

That sequence matters because the attacker could use an already trusted application identity instead of signing in as an ordinary employee.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happened and when

Date Event
March–June 2025 Salesloft’s trust-center account describes reconnaissance involving GitHub tokens, repositories, secrets and cloud-environment credentials. The exact initial intrusion remains attributed to Salesloft and Mandiant.
August 8–18, 2025 Compromised Drift OAuth credentials were used to access and exfiltrate data from some customer Salesforce environments.
August 26, 2025 Salesforce and customers began public incident notifications.
August 28, 2025 Salesforce disabled the Drift connection as a protective measure.
August 28, 2025 Google reported involvement of Drift Email tokens and a limited number of specifically integrated Google Workspace accounts.
September 5–6, 2025 HubSpot reported evidence of unauthorized access through compromised Drift OAuth tokens; Salesloft confirmed containment in its environment on September 6, according to HubSpot’s notice.
April 17, 2026 Salesloft described continuing credential rotation, MFA work, GitHub hardening and log review while Drift remained unavailable pending remediation.
June 17, 2026 Salesforce status material still described the Drift connection as disabled pending remediation and validation.

These dates are not interchangeable: initial access, customer data access, public notification, token revocation and vendor containment are separate events. Sources: Salesloft, Salesloft’s Drift/Salesforce update, Salesforce, and Salesforce status.

Was Salesforce hacked?

Available evidence supports compromise of the Drift application and its credentials. Salesforce said the incident did not originate from a vulnerability in the core Salesforce platform. Nevertheless, a customer Salesforce org could suffer unauthorized access through an approved connected application. Salesforce’s explanation is available in its customer advisory.

So “Salesforce breach” is imprecise. The more accurate description is a Salesloft Drift compromise that abused trusted integrations into customer environments.

How the OAuth attack created a multi-tenant blast radius

1. Upstream compromise

Salesloft and Mandiant describe access involving source-code repositories, tokens, secrets and cloud environments. The complete root-cause narrative should be attributed to those investigators rather than treated as independently established.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Token recovery

The attacker reached Drift’s AWS environment and obtained customer-integration OAuth credentials, according to Salesloft’s account.

3. Application impersonation

Stolen access or refresh tokens allowed API requests through customer-approved Drift connections. A bearer token can authorize requests without a fresh interactive login.

4. Discovery and extraction

Google Threat Intelligence described high-volume API discovery and exfiltration from Salesforce tenants, including searches for credentials and secrets in records, cases and notes. Related reporting is available from Google Cloud.

5. Possible downstream pivots

Passwords, cloud keys, API keys or Snowflake tokens stored in CRM data could enable later attacks. Finding a secret in Salesforce does not prove it was used; investigate each credential separately.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why MFA did not automatically stop it

MFA protects interactive authentication. A previously issued OAuth or refresh token may continue to authorize an application without another MFA prompt. Token grants, connected-app authorizations and sessions therefore require their own inventory and revocation process.

What data may have been exposed?

There is no universal affected-data list. Scope depended on the integration, granted objects and fields, records stored by each tenant, and whether data was queried or exported.

  • Names, business contact details and company attributes
  • Support cases, ticket contents, internal notes and other CRM records
  • Credentials, API keys, cloud tokens or other secrets accidentally stored in Salesforce
  • Data available through Drift Email or specifically integrated Google Workspace accounts

A company may be a direct Drift customer, a Salesforce tenant connected to Drift, a business mentioned in another customer’s records, or a downstream service whose credentials appeared in CRM data. Those categories do not establish the same impact. Toast, Workday and HubSpot published organization-specific findings; their notices should not be generalized.

Who was affected?

The incident involved organizations using relevant Drift integrations, not every Salesforce customer. Public reporting and advisories discussed Cloudflare, Toast, Workday, HubSpot, Palo Alto Networks, Zscaler, Google and other Salesforce customers. A company’s appearance in coverage does not establish identical access or data loss; use that organization’s own notice for scope.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google also reported that Drift Email and a small number of specifically configured Google Workspace accounts were implicated, while Google Workspace and Alphabet themselves were not compromised. See Google’s scope report.

Immediate response checklist

  1. Inventory integrations. Find Salesforce connected apps, Drift Email, Google Workspace links, webhooks, API keys, service accounts and related secrets.
  2. Disable the connection in your own consoles. Do not rely only on a vendor containment statement.
  3. Revoke OAuth grants and refresh tokens. Remove connected-app authorizations and active sessions where supported.
  4. Rotate related secrets. Include Salesforce credentials, cloud and data-platform keys, Google credentials, API keys and any secret stored in CRM records.
  5. Review telemetry. Examine connected-app use, API calls, Bulk API, Data Loader, exports, query jobs and unusual source networks during August 8–18, 2025 and surrounding periods.
  6. Determine data scope. Separate confirmed record reads and exports from merely possible access.
  7. Hunt for downstream use. Check AWS, Google Workspace, Snowflake, identity providers, GitHub, ticketing and other systems for use of exposed credentials.
  8. Preserve evidence. Export logs before retention expires and record notification, revocation and rotation times.
  9. Prepare for phishing. Validate unusual reset, MFA, payment or support requests through an independent channel.

Salesforce directs administrators to Connected Apps and OAuth Usage for reviewing and revoking or rotating tokens: Salesforce guidance.

Salesforce investigation guide

Administrative checks

  • Setup → Connected Apps → OAuth Usage
  • Connected-app policies, profiles and integration users
  • Token issue and last-use timestamps
  • API usage history, Login History and Setup Audit Trail
  • Event Monitoring, if licensed
  • Bulk API, Data Loader, reports, exports and unusual query jobs

Indicators worth investigating

  • Drift-associated OAuth activity during August 8–18, 2025
  • Unfamiliar IP addresses, autonomous systems, Tor, VPN or cloud-provider egress
  • Large API-read volumes or repeated access across many objects
  • Queries involving credentials, support cases, notes or internal fields
  • Bulk exports, Data Loader activity or deleted query jobs

Basic login history may not show application-token activity. Google and Mandiant note that detailed event types can require Salesforce Shield or an Event Monitoring add-on; see their detection guidance.

A suspicious API call proves credential use, not necessarily successful record exfiltration. Conversely, a clean login log does not prove that no API data was accessed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What this teaches about SaaS security

OAuth tokens are production credentials

Inventory access and refresh tokens, minimize scopes, set expiration and rotation policies, monitor issuance and use, and revoke grants during vendor incidents.

Connected applications are a supply chain

Vendor reviews must cover OAuth scopes, integration identities, token lifetime, approval workflow, logging, revocation speed and vendor-side secret management—not only compliance reports and hosting.

Least privilege limits blast radius

Narrow object and action permissions reduce the records, credentials and exports available if an integration is compromised.

CRM data deserves high classification

Salesforce may contain support conversations, contracts, security cases, internal notes and cloud credentials. Classify it by actual contents rather than its sales label.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choosing controls and services

Need Likely fit Important limitation
Detailed Salesforce API and export telemetry Salesforce Shield/Event Monitoring plus SIEM; official page Some event types require premium licensing or add-ons.
Cross-SaaS OAuth inventory and posture SSPM platforms such as AppOmni, Obsidian Security, Adaptive Shield or Wing Security Public pricing was not established; expect quote-based evaluation.
SaaS lifecycle and access management Torii SaaS management is not the same as forensic API-exfiltration detection.
Forensic investigation or containment validation Mandiant or another qualified incident-response provider Scope-based professional services, not a routine inventory tool.
Cross-platform correlation Google Security Operations, Splunk, Microsoft Sentinel or Cortex XSIAM These tools do not automatically inventory or revoke every OAuth grant.

Choose by integration coverage, permission visibility, revocation speed, behavioral detection, data-access analysis, response automation and licensing prerequisites. A tool that cannot show what a connected identity can read—or quickly revoke it—will leave the central Drift lesson unresolved. Google’s broader SaaS threat reporting discusses these control requirements at Cloud Threat Horizons.

Common response mistakes

  • “We never used Drift.” Your data may still appear in another company’s Salesforce records, and similar risks exist in other integrations.
  • “We revoked the token, so we are finished.” Revocation does not erase copied data or invalidate downstream secrets already used.
  • “Our login logs are clean.” Application API activity may be absent from ordinary user-login views.
  • “We reset the integration password.” OAuth tokens, API keys, sessions and embedded CRM secrets may remain valid.
  • “The vendor reported no breach.” That may refer to data stored by the vendor, not customer data accessed through a vendor-issued token.
  • “We should remove every integration.” Replace broad, unmanaged access with an inventory, least-privilege scopes, monitoring and tested revocation procedures.

Current Drift status

Salesloft’s latest cited trust-center material described Drift as offline or unavailable while remediation and validation continued. Check the Salesloft trust center and Salesforce status page for the current wording before reconnecting the service.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.