What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Short answer: The 2025 Salesloft Drift incident was a third-party SaaS and OAuth-token compromise, not evidence that Salesforce’s core platform was hacked. Attackers obtained credentials linked to Salesloft’s Drift environment and replayed trusted application tokens to access some customer Salesforce organizations and other connected services.
The main Salesforce access window reported by Salesloft was August 8–18, 2025. Salesforce disabled the Drift connection on August 28. Exposure depended on whether an organization used an affected integration, the permissions it granted, and the data stored in its connected systems.
The incident in one diagram
Salesloft/Drift systems compromised → OAuth and refresh tokens obtained → attacker impersonates the approved Drift application → customer Salesforce and selected connected SaaS systems queried → records and potentially embedded secrets exfiltrated.
That sequence matters because the attacker could use an already trusted application identity instead of signing in as an ordinary employee.
#1 Best Overall
What happened and when
| Date | Event |
|---|---|
| March–June 2025 | Salesloft’s trust-center account describes reconnaissance involving GitHub tokens, repositories, secrets and cloud-environment credentials. The exact initial intrusion remains attributed to Salesloft and Mandiant. |
| August 8–18, 2025 | Compromised Drift OAuth credentials were used to access and exfiltrate data from some customer Salesforce environments. |
| August 26, 2025 | Salesforce and customers began public incident notifications. |
| August 28, 2025 | Salesforce disabled the Drift connection as a protective measure. |
| August 28, 2025 | Google reported involvement of Drift Email tokens and a limited number of specifically integrated Google Workspace accounts. |
| September 5–6, 2025 | HubSpot reported evidence of unauthorized access through compromised Drift OAuth tokens; Salesloft confirmed containment in its environment on September 6, according to HubSpot’s notice. |
| April 17, 2026 | Salesloft described continuing credential rotation, MFA work, GitHub hardening and log review while Drift remained unavailable pending remediation. |
| June 17, 2026 | Salesforce status material still described the Drift connection as disabled pending remediation and validation. |
These dates are not interchangeable: initial access, customer data access, public notification, token revocation and vendor containment are separate events. Sources: Salesloft, Salesloft’s Drift/Salesforce update, Salesforce, and Salesforce status.
Was Salesforce hacked?
Available evidence supports compromise of the Drift application and its credentials. Salesforce said the incident did not originate from a vulnerability in the core Salesforce platform. Nevertheless, a customer Salesforce org could suffer unauthorized access through an approved connected application. Salesforce’s explanation is available in its customer advisory.
So “Salesforce breach” is imprecise. The more accurate description is a Salesloft Drift compromise that abused trusted integrations into customer environments.
How the OAuth attack created a multi-tenant blast radius
1. Upstream compromise
Salesloft and Mandiant describe access involving source-code repositories, tokens, secrets and cloud environments. The complete root-cause narrative should be attributed to those investigators rather than treated as independently established.
2. Token recovery
The attacker reached Drift’s AWS environment and obtained customer-integration OAuth credentials, according to Salesloft’s account.
3. Application impersonation
Stolen access or refresh tokens allowed API requests through customer-approved Drift connections. A bearer token can authorize requests without a fresh interactive login.
4. Discovery and extraction
Google Threat Intelligence described high-volume API discovery and exfiltration from Salesforce tenants, including searches for credentials and secrets in records, cases and notes. Related reporting is available from Google Cloud.
5. Possible downstream pivots
Passwords, cloud keys, API keys or Snowflake tokens stored in CRM data could enable later attacks. Finding a secret in Salesforce does not prove it was used; investigate each credential separately.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Rank #3
Why MFA did not automatically stop it
MFA protects interactive authentication. A previously issued OAuth or refresh token may continue to authorize an application without another MFA prompt. Token grants, connected-app authorizations and sessions therefore require their own inventory and revocation process.
What data may have been exposed?
There is no universal affected-data list. Scope depended on the integration, granted objects and fields, records stored by each tenant, and whether data was queried or exported.
- Names, business contact details and company attributes
- Support cases, ticket contents, internal notes and other CRM records
- Credentials, API keys, cloud tokens or other secrets accidentally stored in Salesforce
- Data available through Drift Email or specifically integrated Google Workspace accounts
A company may be a direct Drift customer, a Salesforce tenant connected to Drift, a business mentioned in another customer’s records, or a downstream service whose credentials appeared in CRM data. Those categories do not establish the same impact. Toast, Workday and HubSpot published organization-specific findings; their notices should not be generalized.
Who was affected?
The incident involved organizations using relevant Drift integrations, not every Salesforce customer. Public reporting and advisories discussed Cloudflare, Toast, Workday, HubSpot, Palo Alto Networks, Zscaler, Google and other Salesforce customers. A company’s appearance in coverage does not establish identical access or data loss; use that organization’s own notice for scope.
Google also reported that Drift Email and a small number of specifically configured Google Workspace accounts were implicated, while Google Workspace and Alphabet themselves were not compromised. See Google’s scope report.
Immediate response checklist
- Inventory integrations. Find Salesforce connected apps, Drift Email, Google Workspace links, webhooks, API keys, service accounts and related secrets.
- Disable the connection in your own consoles. Do not rely only on a vendor containment statement.
- Revoke OAuth grants and refresh tokens. Remove connected-app authorizations and active sessions where supported.
- Rotate related secrets. Include Salesforce credentials, cloud and data-platform keys, Google credentials, API keys and any secret stored in CRM records.
- Review telemetry. Examine connected-app use, API calls, Bulk API, Data Loader, exports, query jobs and unusual source networks during August 8–18, 2025 and surrounding periods.
- Determine data scope. Separate confirmed record reads and exports from merely possible access.
- Hunt for downstream use. Check AWS, Google Workspace, Snowflake, identity providers, GitHub, ticketing and other systems for use of exposed credentials.
- Preserve evidence. Export logs before retention expires and record notification, revocation and rotation times.
- Prepare for phishing. Validate unusual reset, MFA, payment or support requests through an independent channel.
Salesforce directs administrators to Connected Apps and OAuth Usage for reviewing and revoking or rotating tokens: Salesforce guidance.
Salesforce investigation guide
Administrative checks
- Setup → Connected Apps → OAuth Usage
- Connected-app policies, profiles and integration users
- Token issue and last-use timestamps
- API usage history, Login History and Setup Audit Trail
- Event Monitoring, if licensed
- Bulk API, Data Loader, reports, exports and unusual query jobs
Indicators worth investigating
- Drift-associated OAuth activity during August 8–18, 2025
- Unfamiliar IP addresses, autonomous systems, Tor, VPN or cloud-provider egress
- Large API-read volumes or repeated access across many objects
- Queries involving credentials, support cases, notes or internal fields
- Bulk exports, Data Loader activity or deleted query jobs
Basic login history may not show application-token activity. Google and Mandiant note that detailed event types can require Salesforce Shield or an Event Monitoring add-on; see their detection guidance.
A suspicious API call proves credential use, not necessarily successful record exfiltration. Conversely, a clean login log does not prove that no API data was accessed.
Recommended Free Tools
What this teaches about SaaS security
OAuth tokens are production credentials
Inventory access and refresh tokens, minimize scopes, set expiration and rotation policies, monitor issuance and use, and revoke grants during vendor incidents.
Connected applications are a supply chain
Vendor reviews must cover OAuth scopes, integration identities, token lifetime, approval workflow, logging, revocation speed and vendor-side secret management—not only compliance reports and hosting.
Least privilege limits blast radius
Narrow object and action permissions reduce the records, credentials and exports available if an integration is compromised.
CRM data deserves high classification
Salesforce may contain support conversations, contracts, security cases, internal notes and cloud credentials. Classify it by actual contents rather than its sales label.
Choosing controls and services
| Need | Likely fit | Important limitation |
|---|---|---|
| Detailed Salesforce API and export telemetry | Salesforce Shield/Event Monitoring plus SIEM; official page | Some event types require premium licensing or add-ons. |
| Cross-SaaS OAuth inventory and posture | SSPM platforms such as AppOmni, Obsidian Security, Adaptive Shield or Wing Security | Public pricing was not established; expect quote-based evaluation. |
| SaaS lifecycle and access management | Torii | SaaS management is not the same as forensic API-exfiltration detection. |
| Forensic investigation or containment validation | Mandiant or another qualified incident-response provider | Scope-based professional services, not a routine inventory tool. |
| Cross-platform correlation | Google Security Operations, Splunk, Microsoft Sentinel or Cortex XSIAM | These tools do not automatically inventory or revoke every OAuth grant. |
Choose by integration coverage, permission visibility, revocation speed, behavioral detection, data-access analysis, response automation and licensing prerequisites. A tool that cannot show what a connected identity can read—or quickly revoke it—will leave the central Drift lesson unresolved. Google’s broader SaaS threat reporting discusses these control requirements at Cloud Threat Horizons.
Common response mistakes
- “We never used Drift.” Your data may still appear in another company’s Salesforce records, and similar risks exist in other integrations.
- “We revoked the token, so we are finished.” Revocation does not erase copied data or invalidate downstream secrets already used.
- “Our login logs are clean.” Application API activity may be absent from ordinary user-login views.
- “We reset the integration password.” OAuth tokens, API keys, sessions and embedded CRM secrets may remain valid.
- “The vendor reported no breach.” That may refer to data stored by the vendor, not customer data accessed through a vendor-issued token.
- “We should remove every integration.” Replace broad, unmanaged access with an inventory, least-privilege scopes, monitoring and tested revocation procedures.
Current Drift status
Salesloft’s latest cited trust-center material described Drift as offline or unavailable while remediation and validation continued. Check the Salesloft trust center and Salesforce status page for the current wording before reconnecting the service.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




