TL;DR: Attackers used stolen OAuth tokens from a trusted third-party integration to query Salesforce at scale, harvest embedded secrets, and pivot into connected systems, according to SlashID’s analysis of the UNC6395 campaign and Google Threat Intelligence Group reporting. The breach shows that OAuth trust boundaries, not just login controls, now define the real attack surface for identity teams.
Editorial analysis by NHI Mgmt Group, based on content published by SlashID: “Ready to start a top-tier security upgrade?”.
Key questions
Q: What breaks when SaaS integrations are granted broad OAuth scopes and shared profiles?
A: Broad OAuth scopes and shared integration profiles turn a single compromise into multi-application access.
Q: Why do stolen tokens create more risk than a one-time login compromise?
A: Stolen tokens often bypass the normal interactive login flow, so they can be reused silently until expiration or revocation.
Q: What are the signs that a Salesforce OAuth integration has been abused?
A: Common warning signs include unfamiliar connected apps, dormant apps with broad permissions, unexpected scope elevation, unusually large API exports, login attempts from odd geographies or times, and package installations that bypass security review.
Practitioner guidance
- Tighten OAuth scope baselines Review every third-party integration against the minimum object, field, and API permissions required for its business function.
- Shorten token lifetimes and revoke stale grants Set explicit expiry and rotation expectations for OAuth tokens, then remove integrations that have not been actively validated by the business owner.
- Scan business records for embedded secrets Search Salesforce notes, cases, and exported objects for API keys, cloud tokens, and other machine credentials that may be exposed to integration users.
Bottom line: Over-scoped OAuth integrations can turn a trusted app into a privileged identity path that bypasses normal login-based detection.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Over-scoped OAuth trust is now a primary identity risk, not a secondary app issue. This breach worked because delegated access had been granted more broadly than the business task required, then left live long enough to be abused. The practical conclusion is that identity governance has to follow integration scope, not just user access.
A few things that frame the scale:
- The blast radius of the Salesloft-Drift OAuth supply chain attack was 10 times greater than earlier incidents in which attackers breached Salesforce directly.
A question worth separating out:
Q: How should teams govern third-party SaaS integrations after a token compromise?
A: Treat the integration like a privileged identity, not a convenience feature. Revalidate scope, owner, downstream dependencies, and token lifetime, then remove any connector that can reach unrelated business systems without a clear, current need.
👉 Read our full editorial: Salesforce OAuth token theft shows the cost of over-scoped integrations