Supply chain β›“ Supply Chain

Salesloft Drift OAuth Token Supply Chain Attack

πŸ“… 2025-08-08 🏒 Salesloft Drift (AI chat/sales engagement platform); Salesforce; Google Workspace; Slack
Primary Source β†—

Incident Details

Between August 8–18, 2025, threat actors tracked as UNC6395 exploited compromised OAuth tokens from the Salesloft Drift integration to gain unauthorized access to connected customer environments. More than 700 organizations were affected, including major technology and security vendors such as Cloudflare, Zscaler, Palo Alto Networks, and PagerDuty. Stolen data varied by organization but commonly included business contact records (names, titles, emails, phone numbers), Salesforce CRM data (Accounts, Contacts, Opportunities, Cases), and in some cases API keys, Snowflake tokens, cloud credentials, and passwords embedded in support cases. Salesloft took Drift offline following the discovery. FINRA issued a cybersecurity alert. Organizations were advised to disconnect all Salesloft integrations and rotate exposed credentials.

Technical Details

Initial Attack Vector
UNC6395 compromised Salesloft's Drift AI chatbot integration and stole OAuth authentication tokens used to connect Drift with downstream customer Salesforce, Google Workspace, and Slack environments
Vendor / Product
Salesloft Drift (AI chat/sales engagement platform); Salesforce; Google Workspace; Slack
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-08-08 Breach occurred
  2. 2025-09-01 Publicly disclosed
  3. 2025-09-01 Customers notified