The first entry is always the pin's source. Overall confidence is a weighted average of how firmly each reference supports the start and end times used above; a reference counts half as much for every 180 days older than the newest.
GTIG: 'Beginning as early as Aug. 8, 2025 through at least Aug. 18, 2025, the actor targeted Salesforce customer instances through compromised OAuth tokens associated with the Salesloft[2] Drift third-party application.'
Salesloft's summary of Mandiant's investigation: engaged 26 August 2025, intrusion timeline 22 March to 5 September 2025 including GitHub reconnaissance with Salesloft access tokens, remediation concluded 30 September; Drift came back online on 16 September.
ShinyHunters told BleepingComputer the Drift thefts hit about 760 companies and 1.5 billion Salesforce records; victims confirmed include Google[1], Cloudflare[5], Zscaler, Palo Alto Networks, Tenable and CyberArk.
The FBI confirms UNC6395 used compromised Drift OAuth tokens in August 2025 and that on August 20 Salesloft[2], with Salesforce, revoked all Drift access and refresh tokens.
Cloudflare, notified on 23 August, says the attacker exfiltrated the text of its Salesforce support cases and that it found and rotated 104 Cloudflare API tokens in the stolen data.
Something missing or wrong? Say it in your own words: a link that backs this pin up, a different start or end date and why, or a fact it lacks or gets wrong. The AI checks it against this pin's sources, searches for better ones, and adds any page that backs you up. The pin's own sources still count most.