The Containment Era is here. →Explore

Executive Summary

In early 2025, a significant supply chain breach occurred when threat actor UNC6395 exploited a dormant OAuth token from a third-party Salesloft Drift integration within a Salesforce environment. Leveraging the compromised token—which bypassed MFA—the attacker launched automated connections from multiple unknown VPNs, enumerating CRM accounts and exfiltrating customer data, including embedded credentials. This enabled lateral movement, granting persistent, unauthorized access to hundreds of downstream client Salesforce instances and facilitating privilege escalation into additional systems via harvested secrets.

The incident underscores an urgent trend of attackers exploiting inadequately governed third-party integrations, token sprawl, and absent monitoring. With growing SaaS adoption and rising API-driven architectures, identity-driven supply chain attacks have become top risks, accelerating regulatory scrutiny and industry demand for automated token hygiene, lifecycle management, and more rigorous third-party security postures.

Why This Matters Now

Modern organizations increasingly rely on cloud-native, interconnected SaaS applications, which makes identity tokens and third-party integrations lucrative and vulnerable. Persistent, unmonitored tokens can provide attackers with invisible backdoors, amplifying risk across entire supply chains. Urgent action is needed to monitor, expire, and securely store all access credentials to prevent prolonged, cascading breaches.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach revealed critical weaknesses in token lifecycle management, visibility, and third-party integration governance, exposing gaps against frameworks like NIST 800-53, PCI DSS, and HIPAA concerning secure access control and credential protection.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, egress enforcement, and multicloud visibility controls would have reduced attacker freedom by restricting compromised token access, detecting anomalous activity, and limiting data movement. CNSF-aligned controls help compartmentalize access, enforce least privilege, and provide real-time detection to disrupt this supply-chain attack at multiple points in the kill chain.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Rapid detection of anomalous third-party authentication activity.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Identity-based microsegmentation blocks unnecessary privilege use.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement attempts are blocked or logged for visibility.

Command & Control

Control: Threat Detection & Anomaly Response

Mitigation: C2 activity and suspicious outbound flows are detected and alerted upon.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress filtering stops or delays unauthorized data transfers.

Impact (Mitigations)

Supply-chain blast radius minimized via distributed, real-time enforcement.

Impact at a Glance

Affected Business Functions

  • Customer Relationship Management
  • Sales Operations
  • Customer Support
Operational Disruption

Estimated downtime: 10 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Unauthorized access to sensitive customer data, including contact information, support case details, and embedded credentials such as AWS access keys and passwords, leading to potential data breaches and compliance violations.

Recommended Actions

  • Inventory and continuously monitor all OAuth and API tokens, including those from dormant integrations, to reduce hidden attack surfaces.
  • Apply zero trust segmentation and least privilege policies to third-party connections and enforce identity-based access controls.
  • Enable granular egress security and real-time anomaly detection to identify suspicious outbound data flows quickly.
  • Implement centralized visibility and distributed policy enforcement across all cloud environments and SaaS integrations.
  • Regularly rotate and encrypt all credential artifacts, and establish automated playbooks for rapid revocation in the event of compromise.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image