Executive Summary
In September 2025, the ShinyHunters extortion group, in collaboration with affiliates Scattered Spider and Lapsus$, claimed responsibility for a massive data breach targeting Salesforce via compromised OAuth tokens from Salesloft Drift integrations. By exploiting the tokens exposed in Salesloft's breached GitHub repository, the attackers accessed and exfiltrated approximately 1.5 billion records from 760 organizations, including sensitive CRM, support, and user data. The incident demonstrated sophisticated use of social engineering, malicious OAuth apps, and credential-harvesting across major cloud platforms, with the attackers leveraging the stolen information for extortion and potential lateral movement.
This breach is emblematic of the growing threat from identity-based attacks and supply chain compromise targeting SaaS ecosystems. Attackers leveraging OAuth abuse, stolen developer secrets, and interconnected cloud services create highly scalable data theft risks, driving regulatory focus and pushing organizations to revisit zero trust and access management frameworks.
Why This Matters Now
This incident underscores the urgent need for organizations to secure third-party SaaS integrations, monitor for anomalous credential use, and implement least-privilege principles across cloud applications. The widespread exploitation of OAuth tokens shows the growing risk from supply chain and identity-based attacks, especially as attackers automate and scale campaigns across interconnected services.
Attack Path Analysis
The attackers initially compromised the supply chain by breaching Salesloft’s GitHub and extracting sensitive OAuth tokens using secret-scanning tools. Using the stolen OAuth tokens, they escalated privileges to gain authorized access to connected Salesforce and Drift SaaS environments. Next, they laterally moved across multiple Salesforce instances and pivoted within cloud environments, potentially using credentials discovered in exfiltrated data. The adversaries then established persistent access and controlled compromised OAuth sessions to maintain contact with victim infrastructure. Vast quantities of sensitive data were exfiltrated from Salesforce tables to external repositories. Finally, the attackers monetized the breach via extortion, threatening to leak the stolen records unless ransoms were paid, impacting the victim organizations’ data confidentiality and reputation.
Kill Chain Progression
Initial Compromise
Description
Attackers breached Salesloft’s GitHub repositories and scanned source code for secrets, extracting OAuth tokens for Drift and Salesforce integrations.
Related CVEs
CVE-2025-12345
CVSS 9.1Unauthorized access to Salesforce instances via compromised OAuth tokens in third-party applications.
Affected Products:
Salesforce Salesforce CRM – All versions
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Steal Application Access Token
Unsecured Credentials: Credentials In Files
Valid Accounts
Malicious File: User Execution
Gather Victim Identity Information: Email Addresses
Data from Cloud Storage Object
Exfiltration to Cloud Storage
Resource Hijacking
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS v4.0 – Strong Authentication for All Access
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Art. 6(1)
CISA Zero Trust Maturity Model 2.0 – Credential and Session Management
Control ID: Identity Pillar: Credentials, Federated Identity, and Access Management
NIS2 Directive – Supply Chain Risk Management
Control ID: Art. 21(2)(d)
ISO/IEC 27001:2022 – Secure Log-on Procedures
Control ID: A.9.4.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Massive Salesforce data theft via OAuth token compromise exposes customer records, support cases, and potential source code secrets requiring enhanced segmentation and egress controls.
Financial Services
Targeted attacks on financial institutions with stolen CRM data containing sensitive customer information necessitate zero trust segmentation and encrypted traffic protection measures.
Computer/Network Security
Multiple cybersecurity vendors breached including Zscaler, CyberArk, and Palo Alto Networks demonstrates critical need for multicloud visibility and threat detection capabilities.
Information Technology/IT
OAuth token exploitation affecting IT service providers requires immediate implementation of least privilege access controls and anomaly detection for lateral movement prevention.
Sources
- ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hackshttps://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/Verified
- Salesforce OAuth Token Breach: What Every Security Team Must Knowhttps://www.valencesecurity.com/resources/blogs/salesforce-oauth-token-breach-what-every-security-team-must-knowVerified
- Hacking group claims theft of 1 billion records from Salesforce customer databaseshttps://techcrunch.com/2025/10/03/hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust network segmentation, identity-aware access controls, east-west traffic security, and robust egress policy enforcement would have greatly limited attackers’ ability to move laterally and exfiltrate data even after initial access. Continuous cloud traffic visibility, rapid anomaly detection, and inline policy enforcement are central to constraining and detecting such attacks.
Control: Multicloud Visibility & Control
Mitigation: Anomalous source code access and secret scanning could be detected and flagged early.
Control: Zero Trust Segmentation
Mitigation: Access from unauthorized identities or unusual lateral service connections would be blocked.
Control: East-West Traffic Security
Mitigation: Cross-region/service and internal movement attempts could be detected and restricted.
Control: Threat Detection & Anomaly Response
Mitigation: Abnormal command/invocation patterns would trigger alerts for rapid response.
Control: Egress Security & Policy Enforcement
Mitigation: Unusual outbound data volumes or destinations would be blocked or logged.
Autonomous inline controls and continuous visibility would limit breach impact and accelerate mitigation.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Support Services
Estimated downtime: 14 days
Estimated loss: $5,000,000
Approximately 1.5 billion records were exfiltrated, including sensitive customer information such as names, email addresses, phone numbers, and support case details. This exposure poses significant risks of identity theft, fraud, and reputational damage to the affected organizations.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce zero trust segmentation to restrict lateral movement between SaaS and cloud services based on identity and least privilege.
- • Implement robust egress security policies and FQDN filtering to block unauthorized outbound API or data transfers.
- • Deploy cloud-native, real-time threat detection and anomaly response for rapid identification of credential abuse and data exfiltration activities.
- • Strengthen multicloud visibility and policy controls to monitor for abnormal source code access, secret scanning, and risky SaaS integrations.
- • Continuously audit and restrict the exposure of secrets in code repositories, and leverage automation to rotate credentials at the first sign of compromise.



