Executive Summary
In early 2024, Salesloft experienced a significant cybersecurity breach after attackers compromised a developer's GitHub account. By exploiting weak authentication protocols, threat actors were able to steal OAuth tokens, which enabled them to access and manipulate connected Salesforce instances of downstream customers, resulting in a widespread supply chain attack. The attackers leveraged their foothold to propagate malicious code and gain privileged access to hundreds of enterprise environments, exposing sensitive data and business operations across multiple organizations.
This incident highlights the escalating risk presented by software supply chain attacks, particularly those exploiting code repositories and third-party integrations. It underscores the urgent need for organizations to implement strong access controls, enforce zero trust principles, and continuously monitor code and account activity in their development workflows.
Why This Matters Now
Attacks targeting developer tools and cloud integrations are rapidly rising, making organizations that rely on third-party code or SaaS ecosystems especially vulnerable. As threat groups shift toward supply chain compromise, protecting API keys, OAuth tokens, and development accounts is critical to safeguarding downstream users and maintaining compliance.
Attack Path Analysis
Attackers compromised a developer's GitHub account to gain initial access to sensitive OAuth tokens. Leveraging these credentials, they escalated privileges to access additional systems and sensitive integration points. With expanded access, attackers pivoted laterally through interconnected services and cloud resources. Persistent command and control was established via tokens to maintain remote access and coordination with their infrastructure. OAuth tokens and associated customer data were exfiltrated to attacker-controlled infrastructure. The operational impact affected hundreds of Salesforce instances, resulting in significant supply chain disruption.
Kill Chain Progression
Initial Compromise
Description
Attackers obtained access to a privileged GitHub account, stealing OAuth tokens used for integration with downstream services.
MITRE ATT&CK® Techniques
Credentials In Files
Valid Accounts
Steal Application Access Token
Steal Web Session Cookie
Account Manipulation
Spearphishing Link
Exploit Public-Facing Application
Data from Cloud Storage Object
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Access to System Components
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Program
Control ID: 500.02
DORA (Digital Operational Resilience Act) – IT Risk Management
Control ID: Article 9
CISA Zero Trust Maturity Model (ZTMM) 2.0 – Identity Verification and Access Control
Control ID: Identity Pillar: Authentication
NIS2 Directive – Cybersecurity Risk Management and Reporting
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
GitHub account compromise enabling supply chain attacks directly threatens software development workflows, code repositories, and OAuth token security across development environments.
Marketing/Advertising/Sales
Salesloft breach compromising hundreds of Salesforce instances exposes customer data, sales pipelines, and CRM integrations critical to marketing and sales operations.
Financial Services
Supply chain attacks targeting Salesforce OAuth tokens threaten customer financial data, transaction records, and compliance requirements under PCI and regulatory frameworks.
Health Care / Life Sciences
OAuth token compromise affecting Salesforce instances risks patient data exposure and HIPAA compliance violations through compromised CRM and communication systems.
Sources
- Salesloft Breached via GitHub Account Compromisehttps://www.darkreading.com/cyberattacks-data-breaches/salesloft-breached-github-account-compromiseVerified
- Salesloft says Drift customer data thefts linked to March GitHub account hackhttps://techcrunch.com/2025/09/08/salesloft-says-drift-customer-data-thefts-linked-to-march-github-account-hack/Verified
- Salesloft Drift supply chain attack originated from compromised GitHub accounthttps://www.scworld.com/news/salesloft-drift-supply-chain-attack-originated-from-compromised-github-accountVerified
- Salesloft platform integration restored after probe reveals monthslong GitHub account compromisehttps://www.cybersecuritydive.com/news/salesloft-drift-restored-probe-github/759506/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying Zero Trust Segmentation, workload isolation, east-west traffic controls, and rigorous egress enforcement would have disrupted lateral movement and data exfiltration, while threat detection and visibility could have enabled rapid identification and containment of the attack.
Control: Multicloud Visibility & Control
Mitigation: Facilitates early detection of anomalous account or authentication activity.
Control: Zero Trust Segmentation
Mitigation: Restricts unauthorized privilege escalation by enforcing least-privilege, identity-based access between workloads.
Control: East-West Traffic Security
Mitigation: Prevents or flags lateral movement attempts through workload-to-workload traffic controls.
Control: Threat Detection & Anomaly Response
Mitigation: Generates alerts on suspicious usage patterns, session abuse, or command-and-control behaviors.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks or detects suspicious outbound data exfiltration activity.
Enables rapid, automated enforcement and response to limit blast radius and downstream impact.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Customer Support
Estimated downtime: 10 days
Estimated loss: $5,000,000
Unauthorized access to Salesforce instances led to the exfiltration of sensitive customer data, including contact information, support case details, and potentially embedded credentials such as AWS access keys and Snowflake tokens.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce strict identity-based Zero Trust segmentation to limit token-induced lateral movement between critical SaaS and cloud services.
- • Establish continuous multicloud visibility and centralized monitoring for anomalous authentication and access patterns.
- • Apply granular east-west traffic controls to confine workload communications and rapidly detect unauthorized pivoting.
- • Implement comprehensive egress policy enforcement to block and alert on suspicious data transfers to unauthorized destinations.
- • Deploy adaptive threat detection and automated Cloud Native Security Fabric enforcement to reduce the blast radius and accelerate incident containment.



