✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Marketing/Advertising/Sales
Breach intelligence, attack campaigns, and threat reports targeting the Marketing/Advertising/Sales sector.
Explore Other Sectors
Marketing/Advertising/Sales Threat Reports
Salesloft GitHub Compromise: How a 2025 Supply-Chain Attack Rippled Across 22 Companies
In mid-2025, Salesloft disclosed a significant data breach stemming from a compromise of its GitHub account linked to its Drift application. The incident was investigated by Mandiant, which attributed the activity to the threat actor group UNC6395. Attackers maintained unauthorized access from March through June 2025, enabling them to pivot laterally and potentially compromise sensitive code, data, and operational assets. The breach's supply-chain nature led to downstream impacts, reportedly affecting at least 22 distinct organizations that relied on the compromised software or APIs. This breach highlights the persistent risk posed by supply-chain compromises and stolen developer credentials within cloud ecosystems. With threat actors increasingly targeting development tools and identity-driven pipelines, organizations face mounting regulatory and operational urgency to remediate authentication weaknesses and enforce segmenting policies across their CI/CD toolchains.
6 months ago
Kill Chain
Salesloft Drift OAuth Breach Compromises Salesforce: 2025 Supply Chain Attack Analysis
In August 2025, a supply chain attack leveraging the Salesloft Drift integration was used to compromise customer Salesforce instances. Threat actors exploited compromised OAuth credentials between August 8-18, enabling them to perform automated, high-volume data exfiltration from sensitive Salesforce objects such as Account, Contact, Case, and Opportunity records. Following exfiltration, the attackers reportedly scanned acquired data for credentials and leveraged anti-forensic tactics, including deletion of query logs, to obscure their activities. Salesloft promptly revoked all relevant tokens and notified impacted customers, while security teams advised immediate credential rotations and log investigation for signs of compromise. This incident spotlights the risks associated with third-party SaaS integrations and highlights the sophistication of attackers targeting popular business platforms. As OAuth-based attacks and API exploitations become more common, organizations must enhance supply chain monitoring, review privilege access, and adopt zero trust principles to mitigate similar breaches.
6 months ago
Kill Chain
Salesloft's GitHub Compromise Sparks 2024 Supply Chain Breach
In early 2024, Salesloft experienced a significant cybersecurity breach after attackers compromised a developer's GitHub account. By exploiting weak authentication protocols, threat actors were able to steal OAuth tokens, which enabled them to access and manipulate connected Salesforce instances of downstream customers, resulting in a widespread supply chain attack. The attackers leveraged their foothold to propagate malicious code and gain privileged access to hundreds of enterprise environments, exposing sensitive data and business operations across multiple organizations. This incident highlights the escalating risk presented by software supply chain attacks, particularly those exploiting code repositories and third-party integrations. It underscores the urgent need for organizations to implement strong access controls, enforce zero trust principles, and continuously monitor code and account activity in their development workflows.
6 months ago
Kill Chain
Gambler Panel: The Rise of Affiliate-Driven Scam Gambling Operations in 2025
In July 2025, researchers uncovered a rapid proliferation of fraudulent online gambling platforms connected to a Russia-based affiliate operation called 'Gambler Panel.' This scheme enables thousands of affiliates to launch polished scam gambling sites using a turnkey fake casino engine and aggressive social media lures—often involving fraudulent endorsements and false claims of free credits. Victims are tricked into making cryptocurrency 'verification deposits' which are subsequently stolen, with attempts to cash out consistently denied. The operation is highly organized, offering detailed playbooks and infrastructure supporting over 1,200 domains run by a network of more than 20,000 affiliates. This incident highlights a new, scalable model for financial fraud: cybercriminals outsourcing risk and execution to large affiliate networks via sophisticated, multi-platform campaigns. The case underscores the dangers posed by accessible, turnkey scam infrastructure and the challenges organizations face in monitoring affiliate-driven threat activity targeting consumers globally.
6 months ago
Kill Chain
Inside the 2025 Salesloft Supply Chain Breach: Token Theft at Scale
In August 2025, Salesloft, a leading AI chatbot provider, suffered a significant supply chain compromise when attackers exfiltrated authentication tokens via its Drift integration. The breach allowed unauthorized access to hundreds of customer-connected services, including Salesforce, Slack, Google Workspace, Amazon S3, Azure, and OpenAI, impacting more than 5,000 customers. The attackers, tracked as UNC6395 and possibly linked to ShinyHunters or Scattered Spider, began siphoning sensitive corporate data from at least August 8 to August 18, 2025. The incident led to mass data theft, urgent token invalidation efforts, and subsequent blocking of Drift integrations by Salesforce. This breach highlights the surging threats posed by identity-driven attacks and the risks of over-permissive third-party integrations in the enterprise cloud ecosystem. As attackers increasingly exploit centralized authentication and SSO environments, organizations face urgent pressure to revisit access controls and strengthen detection of abuse within legitimate user sessions.
6 months ago
Kill Chain
Inside the Salesloft Drift Supply Chain Breach: How OAuth Token Theft Exposed SaaS Leaders
In August 2023, the threat group UNC6395 exploited a vulnerability in Salesloft’s Drift SaaS marketing platform, targeting OAuth and refresh tokens stored within its Salesforce integration. By leveraging these stolen tokens, attackers performed lateral movement into several customer Salesforce environments, extracting business contact records, support case data, and in some instances, sensitive configuration details and access credentials from high-profile clients such as Zscaler, Palo Alto Networks, Cloudflare, Proofpoint, and Tenable. Salesloft and Salesforce responded by revoking tokens and disabling integrations, while impacted organizations rushed to assess and mitigate the damage. This incident underscores the persistent risk of supply chain compromises targeting SaaS integrations and identity-based authentication mechanisms. As attackers increasingly leverage token theft for stealthy, authorized access, organizations must adopt granular permissions, token security best practices, and rapid credential rotation to safeguard against similar threats.
6 months ago
Kill Chain
GhostRedirector: Chinese SEO Poisoning Attack Hits Global IIS Web Servers (2024)
In August 2024, a cybercrime group tracked as "GhostRedirector" conducted a widespread SEO poisoning campaign targeting Windows web servers across Brazil, Vietnam, Thailand, and several other regions. The attackers exploited unpatched SQL injection vulnerabilities to gain initial access and deployed custom malware, including Rungan (a C++ backdoor) and Gamshen (a malicious IIS server extension), to maintain persistence and manipulate web content. The campaign's main tactic was to covertly inject links into compromised legitimate websites, boosting the search engine rankings of gambling sites favored by the threat actors. Affected sites span diverse sectors without clear industry targeting, complicating defense strategies. The incident illustrates the persistent risk posed by native IIS module malware and the ongoing evolution of China-based threat actors using advanced web server exploitation and SEO manipulation tactics. Its relevance is heightened by increased attacker interest in manipulating search engine results to drive illicit business revenue and evade detection by blending with legitimate site infrastructure.
6 months ago
Kill Chain
GhostPoster: Malicious Firefox Add-ons Drive 2025 Supply-Chain Breach
In late 2025, security researchers at Koi Security uncovered a widespread supply-chain malware campaign named "GhostPoster." This campaign weaponized 17 Mozilla Firefox browser add-ons, leveraging benign logo files to conceal malicious JavaScript that hijacked affiliate links, injected tracking codes, and orchestrated click and ad fraud operations. The compromised extensions had garnered over 50,000 downloads before Mozilla intervened to remove them from its add-on repository, but users were already exposed to extensive privacy intrusions and potential data exfiltration. The GhostPoster incident underscores a growing trend of exploiting trusted browser extension ecosystems for mass infection and financial fraud. With attackers increasingly targeting supply-chain vectors and browser add-ons, organizations and individuals must reevaluate extension vetting processes amid surging regulatory scrutiny and evolving adversary techniques.
7 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports