TL;DR: UNC6395 abused OAuth tokens tied to Salesloft’s Drift app to query Salesforce data across 700+ organisations and harvested secrets from Cases, including AWS keys, Snowflake tokens, VPN credentials, and passwords, according to Abnormal AI. Trusted integrations can become persistent access paths that bypass gateway controls and credential-based defences until tokens are revoked.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “When Integrations Become Exploits: What the Salesloft Drift Breach Reveals”.
Key questions
Q: What breaks when a stolen OAuth token is used against a trusted integration?
A: The trust model breaks because the system still sees a valid credential, even though the actor behind it is no longer trustworthy.
Q: Why do OAuth tokens create risk even when no phishing email is sent?
A: Because the trust decision was made earlier, often during app onboarding.
Q: What are the signs that a SaaS-to-SaaS integration has been compromised?
A: Look for unusual query volume, bulk data exports, unexpected changes to integration behavior, and access from unfamiliar infrastructure.
Practitioner guidance
- Audit third-party OAuth tokens Inventory every connected SaaS integration, then rank tokens by privilege, data reach and ownership so stale delegated access can be removed first.
- Limit support-case secret exposure Restrict who can query case objects and remove patterns that encourage users to paste API keys, recovery codes or passwords into tickets.
- Revoke unused app permissions Set a recurring review for dormant integrations, excessive scopes and service accounts that can still read mail, CRM data or storage objects.
Bottom line: This breach shows that delegated OAuth access can outlive the trust decision that created it and become a persistent entry point.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Delegated OAuth trust became a persistence layer, not a login convenience. The attacker did not need to defeat primary authentication because the access path already existed in a trusted integration. That shifts the governance problem from user-facing sign-in controls to lifecycle control over issued tokens, scopes and connected-app ownership. The practitioner conclusion is simple: delegated access must be governed as a credential estate.
A few things that frame the scale:
- The blast radius of the Salesloft-Drift OAuth supply chain attack was 10 times greater than earlier incidents in which attackers breached Salesforce directly.
A question worth separating out:
Q: How should teams respond when support data may contain secrets?
A: Treat the support system as a sensitive data repository and reduce who can search, export or query it. Then remove the habit of pasting credentials into tickets, because once a case system becomes a secret store, any compromised integration can become a secret-harvesting path.
👉 Read our full editorial: Salesloft Drift OAuth abuse shows how SaaS trust can collapse