Executive Summary
In early 2025, a significant supply chain breach occurred when threat actor UNC6395 exploited a dormant OAuth token from a third-party Salesloft Drift integration within a Salesforce environment. Leveraging the compromised token—which bypassed MFA—the attacker launched automated connections from multiple unknown VPNs, enumerating CRM accounts and exfiltrating customer data, including embedded credentials. This enabled lateral movement, granting persistent, unauthorized access to hundreds of downstream client Salesforce instances and facilitating privilege escalation into additional systems via harvested secrets.
The incident underscores an urgent trend of attackers exploiting inadequately governed third-party integrations, token sprawl, and absent monitoring. With growing SaaS adoption and rising API-driven architectures, identity-driven supply chain attacks have become top risks, accelerating regulatory scrutiny and industry demand for automated token hygiene, lifecycle management, and more rigorous third-party security postures.
Why This Matters Now
Modern organizations increasingly rely on cloud-native, interconnected SaaS applications, which makes identity tokens and third-party integrations lucrative and vulnerable. Persistent, unmonitored tokens can provide attackers with invisible backdoors, amplifying risk across entire supply chains. Urgent action is needed to monitor, expire, and securely store all access credentials to prevent prolonged, cascading breaches.
Attack Path Analysis
The attack began with threat actors obtaining a dormant third-party OAuth token from an external integration, granting themselves initial access to connected Salesforce environments. Using this legitimate token, they escalated privileges to enumerate and interact with sensitive CRM data and embedded credentials. The adversaries leveraged this access to pivot between interconnected cloud assets by exploiting inadequate internal controls and monitoring, enabling lateral movement. They established outbound command and control by obscuring exfiltration traffic across multiple IPs, including via VPN services. Substantial volumes of sensitive data were then exported from the environment. The compromise resulted in significant business and reputational impact due to downstream data breach effects across the supply chain.
Kill Chain Progression
Initial Compromise
Description
Threat actors stole a dormant OAuth token associated with a third-party SaaS integration, gaining unauthorized access into connected Salesforce environments.
MITRE ATT&CK® Techniques
Implant Internal Image
Create Cloud Account: Cloud Account
Use Alternate Authentication Material: Web Session Cookie
Valid Accounts: Cloud Accounts
Data from Cloud Storage Object
Exfiltration Over C2 Channel
Account Manipulation
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Secure management of account and authentication credentials
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy, Access Privileges, and Risk Assessment
Control ID: 500.03, 500.07, 500.09
DORA (Regulation (EU) 2022/2554) – Risk Management Framework and ICT Third-Party Risk
Control ID: Article 6; Article 28
CISA Zero Trust Maturity Model 2.0 – Continuous Identity Protection and Credential Governance
Control ID: Identity Pillar (Identity, Credential, and Access Management - ICAM)
NIS2 Directive – Asset Management, Access Control, and Supply Chain Security
Control ID: Article 21, Section 2(d)(e)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Third-party OAuth token compromises expose SaaS integrations to supply-chain attacks, bypassing MFA through dormant connections and enabling lateral movement across customer environments.
Financial Services
Compromised OAuth tokens in CRM systems risk exposing sensitive financial data and customer credentials, violating PCI compliance while enabling data exfiltration through trusted integrations.
Information Technology/IT
IT service providers face cascading supply-chain risks from insecure token management, potentially exposing multiple client environments through compromised third-party application integrations and API access.
Health Care / Life Sciences
Healthcare organizations risk HIPAA violations through compromised OAuth tokens accessing patient data in integrated systems, requiring immediate token rotation and compliance audit procedures.
Sources
- Trusted Connections, Hidden Risks: Token Management in the Third-Party Supply Chainhttps://unit42.paloaltonetworks.com/third-party-supply-chain-token-management/Verified
- Hackers Use Compromised Salesloft, Drift OAuth Tokens to Breach Salesforce Datahttps://cyberpress.org/breach-salesforce-data/Verified
- Even Cloudflare isn't safe from Salesloft Drift data breacheshttps://www.techradar.com/pro/security/even-cloudflare-isnt-safe-from-salesloft-drift-data-breachesVerified
- Google warns Salesloft attack may have compromised Workspace accounts and Salesforce instanceshttps://www.techradar.com/pro/security/google-warns-salesloft-attack-may-have-compromised-workspace-accounts-and-salesforce-instancesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, egress enforcement, and multicloud visibility controls would have reduced attacker freedom by restricting compromised token access, detecting anomalous activity, and limiting data movement. CNSF-aligned controls help compartmentalize access, enforce least privilege, and provide real-time detection to disrupt this supply-chain attack at multiple points in the kill chain.
Control: Multicloud Visibility & Control
Mitigation: Rapid detection of anomalous third-party authentication activity.
Control: Zero Trust Segmentation
Mitigation: Identity-based microsegmentation blocks unnecessary privilege use.
Control: East-West Traffic Security
Mitigation: Lateral movement attempts are blocked or logged for visibility.
Control: Threat Detection & Anomaly Response
Mitigation: C2 activity and suspicious outbound flows are detected and alerted upon.
Control: Egress Security & Policy Enforcement
Mitigation: Egress filtering stops or delays unauthorized data transfers.
Supply-chain blast radius minimized via distributed, real-time enforcement.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Customer Support
Estimated downtime: 10 days
Estimated loss: $5,000,000
Unauthorized access to sensitive customer data, including contact information, support case details, and embedded credentials such as AWS access keys and passwords, leading to potential data breaches and compliance violations.
Recommended Actions
Key Takeaways & Next Steps
- • Inventory and continuously monitor all OAuth and API tokens, including those from dormant integrations, to reduce hidden attack surfaces.
- • Apply zero trust segmentation and least privilege policies to third-party connections and enforce identity-based access controls.
- • Enable granular egress security and real-time anomaly detection to identify suspicious outbound data flows quickly.
- • Implement centralized visibility and distributed policy enforcement across all cloud environments and SaaS integrations.
- • Regularly rotate and encrypt all credential artifacts, and establish automated playbooks for rapid revocation in the event of compromise.



