Executive Summary
In August 2023, the threat group UNC6395 exploited a vulnerability in Salesloft’s Drift SaaS marketing platform, targeting OAuth and refresh tokens stored within its Salesforce integration. By leveraging these stolen tokens, attackers performed lateral movement into several customer Salesforce environments, extracting business contact records, support case data, and in some instances, sensitive configuration details and access credentials from high-profile clients such as Zscaler, Palo Alto Networks, Cloudflare, Proofpoint, and Tenable. Salesloft and Salesforce responded by revoking tokens and disabling integrations, while impacted organizations rushed to assess and mitigate the damage.
This incident underscores the persistent risk of supply chain compromises targeting SaaS integrations and identity-based authentication mechanisms. As attackers increasingly leverage token theft for stealthy, authorized access, organizations must adopt granular permissions, token security best practices, and rapid credential rotation to safeguard against similar threats.
Why This Matters Now
The Salesloft Drift supply chain attack highlights the urgent need for organizations to secure inter-SaaS integrations, as identity and token theft have become preferred pathways for sophisticated threat actors. Increased reliance on third-party platforms exposes enterprises to downstream breaches, making vigilant monitoring and zero trust practices essential in today’s threat landscape.
Attack Path Analysis
Attackers initially compromised Drift’s integration by stealing OAuth and refresh tokens from Salesloft’s Salesforce integration via a supply-chain vulnerability. Using these stolen tokens, the attackers escalated privileges to access customer data with legitimate-looking authentication. They then moved laterally into connected customer SaaS environments leveraging the compromised tokens across integrated applications. Command and control was maintained by making API calls and possibly using cloud-hosted infrastructure to blend in with legitimate traffic. The threat actors exfiltrated customer contact and support data, including sensitive config details and potential access tokens through API or SaaS data exports. The overall impact was unauthorized disclosure of business information, enabling potential downstream social engineering and persistent risk across the supply chain.
Kill Chain Progression
Initial Compromise
Description
Threat actor exploited a supply chain weakness in the Drift integration to steal OAuth and refresh tokens from the Salesloft-Salesforce connection.
MITRE ATT&CK® Techniques
Valid Accounts: Cloud Accounts
Use Alternate Authentication Material: Web Sessions
Brute Force: Password Spraying
Trusted Relationship
System Shutdown/Reboot
Data from Cloud Storage
Exfiltration Over C2 Channel
Phishing: Spearphishing Attachment
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Users and Administrators
Control ID: 8.3.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management
Control ID: Article 6
CISA ZTMM 2.0 – Session and Token Management
Control ID: Identity Pillar - 3.3
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
ISO/IEC 27001:2022 – Information Security in Supplier Relationships
Control ID: A.15.1.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Supply chain attacks targeting SaaS platforms expose OAuth tokens, enabling lateral movement into customer environments and compromising software integrations across the industry.
Information Technology/IT
IT service providers face elevated risks from compromised authentication tokens in customer management systems, potentially exposing client data and configurations.
Computer/Network Security
Cybersecurity vendors become high-value targets as breached customer support systems may expose sensitive security configurations, tokens, and threat intelligence data.
Marketing/Advertising/Sales
Marketing automation platforms vulnerable to OAuth token theft through Salesforce integrations, exposing customer contact data and enabling sophisticated social engineering attacks.
Sources
- Blast Radius of Salesloft Drift Attacks Remains Uncertainhttps://www.darkreading.com/cyberattacks-data-breaches/salesloft-drift-attacks-blast-radius-uncertainVerified
- Salesloft Drift supply chain attack originated from compromised GitHub accounthttps://www.scworld.com/news/salesloft-drift-supply-chain-attack-originated-from-compromised-github-accountVerified
- Cybersecurity Alert – Salesloft Drift AI Supply Chain Attackhttps://www.finra.org/rules-guidance/guidance/salesloft-drift-AI-supply-chain-attackVerified
- Salesloft breached to steal OAuth tokens for Salesforce data-theft attackshttps://www.techradar.com/pro/security/salesloft-breached-to-steal-oauth-tokens-for-salesforce-data-theft-attacksVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Comprehensive Zero Trust segmentation, egress policy enforcement, and real-time anomaly detection could have severely constrained token abuse, lateral movement, and data exfiltration, limiting the supply chain blast radius. CNSF-aligned controls—such as identity-based segmentation, east-west workload isolation, egress filtering, and distributed visibility—would improve detection and prevention of unauthorized activities, even when attackers use valid credentials.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline policy and distributed enforcement could detect or restrict anomalous token flows.
Control: Zero Trust Segmentation
Mitigation: Least-privilege access boundaries prevent stolen tokens from granting broad access.
Control: East-West Traffic Security
Mitigation: Workload-to-workload traffic control blocks unauthorized lateral movement.
Control: Threat Detection & Anomaly Response
Mitigation: Anomaly detection raises real-time alerts on unauthorized or unusual API usage patterns.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound traffic filters and policy enforcement stop or alert on unapproved data flows.
Unified cross-cloud visibility and centralized log analysis rapidly scope and contain blast radius.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Customer Support
Estimated downtime: 10 days
Estimated loss: $5,000,000
Unauthorized access to Salesforce instances led to the exfiltration of sensitive data, including customer contact information, support case details, and embedded credentials such as API keys and access tokens. This exposure increases the risk of credential stuffing, spear phishing, and social engineering attacks against affected organizations and their clients.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce strict Zero Trust segmentation and least-privilege access policies on all SaaS, cloud, and integration points.
- • Implement continuous east-west workload traffic inspection and restrict movement using identity-aware policies.
- • Mandate egress filtering and protocol restriction to detect or block unauthorized data flows, even from trusted integrations.
- • Deploy distributed, real-time anomaly detection to identify abnormal SaaS API usage and rapidly trigger incident response.
- • Centralize multicloud visibility and automate credential/token revocation to minimize blast radius during future integration breaches.



