元のタイトル: Hackers Use Stolen Salesloft Drift Tokens to Raid Salesforce Instances
最初の項目は常にピンの出典です。全体の確度は、各資料が上記の開始・終了時刻をどれだけ強く裏付けているかの加重平均です。最新の資料より180日古くなるごとに、重みは半分になります。
GTIGによれば、「2025年8月8日ごろから少なくとも2025年8月18日まで、攻撃者はサードパーティ製アプリケーションSalesloft[2] Driftに関連する侵害されたOAuthトークンを通じて、Salesforceの顧客インスタンスを標的にした」。
Salesloft's summary of Mandiant's investigation: engaged 26 August 2025, intrusion timeline 22 March to 5 September 2025 including GitHub reconnaissance with Salesloft access tokens, remediation concluded 30 September; Drift came back online on 16 September.
ShinyHunters told BleepingComputer the Drift thefts hit about 760 companies and 1.5 billion Salesforce records; victims confirmed include Google[1], Cloudflare[5], Zscaler, Palo Alto Networks, Tenable and CyberArk.
The FBI confirms UNC6395 used compromised Drift OAuth tokens in August 2025 and that on August 20 Salesloft[2], with Salesforce, revoked all Drift access and refresh tokens.
Cloudflare, notified on 23 August, says the attacker exfiltrated the text of its Salesforce support cases and that it found and rotated 104 Cloudflare API tokens in the stolen data.
足りない点や誤りがありますか? このピンを裏付けるリンク、別の開始日・終了日とその理由、欠けている情報や誤っている情報を、自由に書いてください。AIがこのピンの出典と照らし合わせ、より良い情報源を探し、裏付けとなるページがあれば参考資料として追加します。ピン自身の出典が引き続き最も重視されます。