Hackers Use Stolen Salesloft Drift Tokens to Raid Salesforce Instances
CONFIRMED87% CONFIDENCEGTIG: 'Beginning as early as Aug. 8, 2025 through at least Aug. 18, 2025, the actor targeted Salesforce customer instances through compromised OAuth tokens associated with the Salesloft[2] Drift third-party application.'
Using OAuth tokens stolen from Salesloft's Drift chatbot, the UNC6395 crew exported data from hundreds of companies' Salesforce instances, hunting support cases for AWS keys, passwords and Snowflake tokens.
1.00