Executive Summary
In early 2024, a sophisticated supply chain attack targeted the Salesloft and Drift integration, leading to the compromise of AWS credentials and unauthorized access to cloud environments. Threat actors exploited weaknesses in the integration pipeline, leveraging exposed secrets to move laterally and access sensitive customer data before the breach became public. Red Canary detected anomalous cloud activity tied to this attack, providing early detection prior to broad public awareness and response, thereby helping to mitigate further impact.
This incident is significant as it demonstrates the growing frequency and sophistication of supply chain attacks within SaaS and cloud services, especially those exploiting secret leaks and third-party application integrations. The breach highlights the need for heightened vigilance, identity and credential protection, and advanced threat detection capabilities in the cloud ecosystem.
Why This Matters Now
Supply chain attacks targeting cloud integrations are rapidly increasing, enabling attackers to bypass traditional defenses through trusted third-party channels. With organizations relying more on SaaS and cloud-native integrations, credential exposure and lack of east-west visibility become high-risk vectors. Immediate adoption of zero trust, threat detection, and multicloud policy enforcement is essential.
Attack Path Analysis
Attackers gained initial access via a compromised third-party vendor that exposed AWS secrets as part of a software supply chain attack. They leveraged these credentials to escalate privileges within the cloud environment, obtaining broader access. The adversary then moved laterally across workloads, potentially accessing additional services and data resources using discovered keys. Establishing command and control, covert outbound channels were set up to communicate with attacker infrastructure. Sensitive data such as secrets and configuration files were exfiltrated through egress or cloud-native services. Finally, operations potentially impacted business services or resulted in further unauthorized supply chain compromise.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited the supply chain by stealing or discovering confidential AWS credentials exposed via a third-party tool or integration.
MITRE ATT&CK® Techniques
Supply Chain Compromise: Compromise of Software Dependencies and Development Tools
Unsecured Credentials: Credentials In Files
Valid Accounts: Cloud Accounts
Account Discovery: Cloud Account
Exfiltration Over Alternative Protocol
Modify Authentication Process: Web Portal
Automated Exfiltration
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Users and Administrators
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 6
CISA Zero Trust Maturity Model 2.0 – Identity Access Management – Policy Enforcement
Control ID: Pillar: Identity (Level: Traditional)
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
TruffleHog AWS supply chain attacks target software development infrastructure, compromising source code repositories and CI/CD pipelines with credential harvesting.
Information Technology/IT
IT services face elevated risks from cloud-based supply chain compromises affecting AWS environments, requiring enhanced threat detection and egress security.
Marketing/Advertising/Sales
Salesloft Drift supply chain attack directly impacts sales technology platforms, exposing customer data and requiring zero trust segmentation implementations.
Financial Services
Supply chain attacks threaten financial infrastructure through compromised third-party integrations, necessitating enhanced multicloud visibility and compliance controls.
Sources
- Sniffing out TruffleHog in AWShttps://redcanary.com/blog/threat-detection/trufflehog-aws/Verified
- Cybersecurity Alert – Salesloft Drift AI Supply Chain Attackhttps://www.finra.org/rules-guidance/guidance/salesloft-drift-AI-supply-chain-attackVerified
- Salesloft Drift supply chain attack originated from compromised GitHub accounthttps://www.scworld.com/news/salesloft-drift-supply-chain-attack-originated-from-compromised-github-accountVerified
- Salesloft Drift supply chain attack leads to widespread data thefthttps://www.mwe.com/insights/salesloft-drift-supply-chain-attack-leads-to-widespread-data-theft/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Zero Trust segmentation, comprehensive egress policy enforcement, threat detection, and encrypted traffic controls would have significantly restricted lateral movement, privilege abuse, and data exfiltration within the cloud—effectively containing adversary actions at multiple kill chain stages.
Control: Threat Detection & Anomaly Response
Mitigation: Early detection of anomalous cloud API usage or credential exfiltration.
Control: Zero Trust Segmentation
Mitigation: Prevents over-permissioned lateral escalation between cloud services.
Control: East-West Traffic Security
Mitigation: Limits and monitors unauthorized internal traffic between workloads.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks unauthorized outbound C2 channels.
Control: Encrypted Traffic (HPE)
Mitigation: Detects and logs anomalous data flows, prevents unencrypted sensitive data egress.
Accelerates detection and limits blast radius of supply chain impacts.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Customer Support
Estimated downtime: 10 days
Estimated loss: $5,000,000
Unauthorized access to Salesforce instances led to the exfiltration of sensitive customer data, including contact information, account records, and support case details. This exposure increases the risk of credential stuffing, spear phishing, and social engineering attacks against affected organizations and their clients.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust segmentation and microsegmentation to contain lateral movement between sensitive workloads and environments.
- • Apply comprehensive egress filtering and encryption controls to restrict malicious outbound communications and prevent data leakage.
- • Continuously monitor for anomalous access patterns and credential use with real-time threat detection and automated response.
- • Implement granular, identity-based access policies and restrict privileges according to least privilege principles throughout the cloud supply chain.
- • Centralize policy and observability across multicloud and hybrid environments to accelerate risk detection and response to supply chain threats.



