Executive Summary
In August 2025, a supply chain attack leveraging the Salesloft Drift integration was used to compromise customer Salesforce instances. Threat actors exploited compromised OAuth credentials between August 8-18, enabling them to perform automated, high-volume data exfiltration from sensitive Salesforce objects such as Account, Contact, Case, and Opportunity records. Following exfiltration, the attackers reportedly scanned acquired data for credentials and leveraged anti-forensic tactics, including deletion of query logs, to obscure their activities. Salesloft promptly revoked all relevant tokens and notified impacted customers, while security teams advised immediate credential rotations and log investigation for signs of compromise.
This incident spotlights the risks associated with third-party SaaS integrations and highlights the sophistication of attackers targeting popular business platforms. As OAuth-based attacks and API exploitations become more common, organizations must enhance supply chain monitoring, review privilege access, and adopt zero trust principles to mitigate similar breaches.
Why This Matters Now
The compromise of OAuth tokens in widespread SaaS integrations like Salesloft and Drift exposes the increasing systemic risks in cloud supply chains. Immediate action is required because similar attack methods are proliferating, attackers are bypassing traditional controls, and mass data exfiltration can occur with minimal detection or forensic trace, raising the urgency for stronger third-party risk management and granular access monitoring.
Attack Path Analysis
The attack began when a threat actor obtained compromised OAuth credentials for the Salesloft Drift integration, allowing initial unauthorized access to connected Salesforce environments. With these credentials, the attacker was able to operate with elevated privileges associated with the OAuth app, granting broad access to Salesforce records. The actor likely moved laterally within the Salesforce tenant to access and aggregate additional sensitive data objects. The adversary established command and control by utilizing automation and APIs (Python aiohttp scripts) through authorized channels. Massive volumes of sensitive Salesforce data were then exfiltrated using the Bulk API. Finally, the attacker deleted evidence and query logs as an anti-forensics measure, impacting situational awareness and security monitoring.
Kill Chain Progression
Initial Compromise
Description
Threat actor acquired and abused compromised OAuth credentials linked to the Salesloft Drift app integration, gaining initial access to Salesforce instances.
MITRE ATT&CK® Techniques
Access Token Abuse
Exploit Public-Facing Application
Remote Services: Remote Services (SaaS)
Email Collection: Cloud Email Provider
Transfer Data to Cloud Account
Indicator Removal: File Deletion
Unsecured Credentials: Credentials in Files
Phishing
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Respond to security incidents
Control ID: 12.10.5
NYDFS 23 NYCRR 500 – Risk Assessment
Control ID: 500.09
DORA (Digital Operational Resilience Act) – ICT Third-Party Risk Management
Control ID: Article 27
CISA ZTMM 2.0 – Monitor and Protect Credentials and Access Tokens
Control ID: Identity 1.3
NIS2 Directive – Security in Network and Information Systems
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Supply chain attacks targeting SaaS integrations like Salesloft-Salesforce create critical vulnerabilities in software platforms, requiring enhanced OAuth security and API monitoring capabilities.
Financial Services
Mass exfiltration of customer contact and opportunity data through compromised integrations exposes sensitive financial information, demanding immediate credential rotation and compliance validation.
Marketing/Advertising/Sales
Direct compromise of Salesloft Drift integration threatens core CRM operations, exposing account, contact, and opportunity records essential for sales and marketing activities.
Professional Training
Organizations using Salesforce for client management face data breach risks from third-party integrations, necessitating enhanced visibility and threat detection for educational service providers.
Sources
- Threat Brief: Salesloft Drift Integration Used To Compromise Salesforce Instanceshttps://unit42.paloaltonetworks.com/threat-brief-compromised-salesforce-instances/Verified
- Salesloft says Drift customer data thefts linked to March GitHub account hackhttps://techcrunch.com/2025/09/08/salesloft-says-drift-customer-data-thefts-linked-to-march-github-account-hack/Verified
- Widespread Data Theft Targets Salesforce Instances via Salesloft Drifthttps://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-driftVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west traffic security, egress policy enforcement, and multicloud visibility would have significantly limited the attacker's ability to access, exfiltrate, and conceal data at scale. Distributed policy and inline inspection would have provided detection and containment throughout the kill chain before mass data loss or anti-forensics occurred.
Control: Multicloud Visibility & Control
Mitigation: Centralized monitoring would have detected unauthorized app access.
Control: Zero Trust Segmentation
Mitigation: Identity-based policy would restrict lateral privileges for integration apps.
Control: East-West Traffic Security
Mitigation: Lateral movement between sensitive resources is monitored and can be blocked.
Control: Threat Detection & Anomaly Response
Mitigation: Automated detection alerts on high-volume API usage and unusual patterns.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound data exfiltration attempts are detected and can be blocked.
Centralized log aggregation aids rapid detection of anti-forensic actions.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Support Services
Estimated downtime: 10 days
Estimated loss: $5,000,000
Unauthorized access to sensitive customer data, including contact information, support case details, and embedded credentials such as AWS access keys and Snowflake tokens.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce least-privilege access and granular zero trust segmentation for all SaaS and integration accounts.
- • Implement centralized multicloud visibility and continuous monitoring of all API and OAuth integrations.
- • Apply east-west traffic security and workload-to-workload controls to monitor and restrict lateral movement.
- • Enable robust egress filtering and policy enforcement to detect and block suspicious data export activity.
- • Continuously monitor for anomalous behaviors, baseline integration traffic, and perform regular threat hunting using consolidated cloud logs.



