Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Salesloft Drift Breach 2025: How Stolen OAuth Tokens…
Breach analysis Incident: 8 Aug 2025

Salesloft Drift Breach 2025: How Stolen OAuth Tokens From One Chatbot Integration Opened Hundreds of Salesforce Tenants

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 12 min read
Category: NHI
On this page

Between 8 and 18 August 2025, a threat actor that Google Threat Intelligence Group tracks as UNC6395 used stolen OAuth access and refresh tokens belonging to the Salesloft Drift chatbot integration to export data from the Salesforce instances of many organisations. Google cited over 700 potentially impacted organisations. The actor then searched the stolen records for AWS keys, passwords and Snowflake tokens. Salesloft's later investigation with Mandiant found that the intruder had been in Salesloft's GitHub account from March to June 2025 and then reached Drift's AWS environment, where the customer integration tokens were held. Cloudflare, Zscaler and Palo Alto Networks were among the disclosed victims. No user was phished and no Salesforce flaw was exploited: the attacker simply held a trusted integration's tokens.

Key takeaways

  • Data theft ran from 8 to 18 August 2025, according to Google Threat Intelligence Group and Salesloft. Salesloft and Salesforce revoked all active Drift access and refresh tokens on 20 August 2025.
  • According to Salesloft, the root cause was an intrusion into its GitHub account between March and June 2025, followed by theft of customer integration tokens from Drift's AWS environment.
  • The identities abused were non-human: OAuth tokens for the Drift Salesforce integration and, on 9 August 2025, tokens for the Drift Email integration with Google Workspace.
  • The actor mined exported data, including support cases, for secrets. Cloudflare alone rotated 104 of its own API tokens found in it.
  • This is a different campaign from the ShinyHunters voice phishing attacks on Salesforce customers. Google said it had not seen "any compelling evidence" connecting the two.

At a glance

OrganisationSalesloft (Drift product); downstream victims included Cloudflare, Zscaler, Palo Alto Networks and many other Salesforce customers using the Drift integration
WhenSalesloft GitHub account accessed March to June 2025; Salesforce data theft 8 to 18 August 2025; tokens revoked 20 August 2025
AttackerUNC6395, as tracked by Google Threat Intelligence Group; Cloudflare tracks the same activity as GRUB1
Entry pointSalesloft's GitHub account, then Drift's AWS environment, where OAuth tokens for customer integrations were stored
Identities abusedOAuth access and refresh tokens for the Drift Salesforce integration; OAuth tokens for the Drift Email integration with Google Workspace; secrets found inside exported CRM records
ImpactBulk export of Salesforce records such as accounts, contacts, opportunities, users and support cases from many organisations; Google cited over 700 potentially impacted organisations
CategoryNHI (OAuth integration tokens, API keys and cloud credentials), SaaS supply chain

What happened

Drift is a chatbot product owned by Salesloft. Customers connect it to Salesforce and other platforms through OAuth, so Drift holds tokens that act on their data. Whoever holds those tokens can do the same.

On 20 August 2025, Salesloft said it had detected a security issue in the Drift application and, in collaboration with Salesforce, had taken action to "proactively revoke all active access and refresh tokens for the Drift application." GTIG reported that Salesforce also removed Drift from its AppExchange pending investigation. Salesloft later said that "From August 8 to August 18, 2025, a threat actor used OAuth credentials to exfiltrate data from our customers' Salesforce instances."

Google Threat Intelligence Group (GTIG) published its analysis on 26 August 2025. It said UNC6395 "systematically exported large volumes of data from numerous corporate Salesforce instances" and that the main aim was to harvest credentials. The actor first ran count queries against the Account, Opportunity, User and Case objects, then pulled records in bulk, using tools that included one identifying itself as Salesforce-Multi-Org-Fetcher/1.0. Tyler McLellan of GTIG told CyberScoop: "Using a single token stolen from Salesloft, the threat actor was able to access tokens for any Drift linked organization." Austin Larsen of GTIG said: "GTIG is aware of over 700 potentially impacted organizations."

The actor then searched the data for secrets. GTIG lists AWS access keys (strings beginning AKIA), passwords and Snowflake-related access tokens. Support cases were a rich source, because, as Cloudflare put it, "customers may paste keys, logs, or other sensitive information into the case text fields."

The scope widened on 28 August 2025. GTIG said its investigation "confirmed that the actor also compromised OAuth tokens for the 'Drift Email' integration", and that on 9 August 2025 the actor had used them to access email from a very small number of Google Workspace accounts. Google revoked those tokens, disabled the integration and told all Drift customers to "treat any and all authentication tokens stored in or connected to the Drift platform as potentially compromised." Salesforce, as a precaution, also temporarily disabled all Salesloft integrations with Salesforce.

On 6 September 2025, Salesloft published the first results of the Mandiant investigation. It said that from March to June 2025 "the threat actor accessed the Salesloft GitHub account" and was able to download content from multiple repositories, add a guest user and establish workflows. The actor then "accessed Drift's AWS environment and obtained OAuth tokens for Drift customers' technology integrations." Salesloft said the intrusion timeline ran from 22 March to 5 September 2025 and included API calls from TOR and anonymising proxies. It has not said how the GitHub account was first compromised.

Salesloft took Drift offline on 5 September 2025, rotated impacted credentials and said Mandiant had verified the "technical segmentation between Salesloft and Drift applications and infrastructure environments." SecurityWeek reported the Salesforce integration was restored on 7 September; Drift returned on 16 September 2025.

ShinyHunters first hinted to BleepingComputer that the incident was theirs, then said it was not linked to them as they were "not targeting support cases." GTIG said it had "not seen any compelling evidence connecting them at this time." The Drift token theft is therefore separate from the ShinyHunters Salesforce data theft campaign, in which attackers used voice phishing "to trick employees into linking a malicious OAuth app" to Salesforce, as BleepingComputer describes. The Drift campaign needed no help from any victim employee.

Timeline

DateEvent
22 March 2025Start of the intrusion timeline identified by Salesloft and Mandiant, including API calls from TOR and anonymising proxies.
March to June 2025Actor accesses Salesloft's GitHub account and carries out reconnaissance; later reaches Drift's AWS environment and obtains customer integration tokens (date not published).
8 to 18 August 2025UNC6395 uses Drift OAuth tokens to export data from customers' Salesforce instances; Cloudflare saw its first token verification attempt on 9 August and data access from 12 to 17 August.
9 August 2025Actor uses Drift Email OAuth tokens to access a very small number of Google Workspace accounts, according to GTIG.
20 August 2025Salesloft and Salesforce revoke all active access and refresh tokens for the Drift application.
26 August 2025GTIG publishes its UNC6395 advisory; Google cites over 700 potentially impacted organisations.
28 August 2025GTIG confirms the Drift Email compromise and advises treating all Drift-connected tokens as compromised.
30 August to 2 September 2025Zscaler, Cloudflare and Palo Alto Networks publicly disclose that their Salesforce data was accessed.
5 to 7 September 2025Drift taken offline on 5 September; Salesloft publishes Mandiant findings on 6 September; Salesforce integration with Salesloft restored on 7 September.
16 September 2025Drift brought back online with core chat and reporting capabilities.

How it happened: the identity attack path

  1. A code platform account taken over. The actor held Salesloft's GitHub account from March to June 2025, adding a guest user and creating workflows. How it first got in has not been disclosed.
  2. From source control to cloud. After reconnaissance, the actor reached Drift's AWS environment. Salesloft has not published exactly how.
  3. Integration tokens harvested in one place. In AWS the actor obtained OAuth tokens for Drift customers' technology integrations. One environment held the keys to many tenants.
  4. Legitimate API access to victim CRMs. UNC6395 called Salesforce APIs as the trusted Drift application and exported records in bulk. Salesforce said the issue "did not stem from a vulnerability within the core Salesforce platform", but from a compromise of the app's connection.
  5. Secrets mined from the loot. The actor searched exported records, especially support cases, for AWS keys, passwords and Snowflake tokens that could open further systems.
  6. Other integrations in reach. Drift Email tokens let the actor into Google Workspace accounts on 9 August 2025.

Impact

The exact number of organisations whose data was taken has not been published. Google said on 26 August 2025 that it was aware of over 700 potentially impacted organisations. SecurityWeek listed more than a dozen security firms among confirmed victims, including Cloudflare, Palo Alto Networks, Zscaler, Proofpoint, Tenable, CyberArk and Elastic.

Victim disclosures describe similar data. Cloudflare said exposure was limited to Salesforce support case objects, with no attachments accessed; it rotated 104 Cloudflare API tokens found in the data and saw no misuse. Zscaler said the tokens "allowed limited access to some Zscaler Salesforce information", mainly contact, licensing and support case header data. Palo Alto Networks said, as reported by The Register, that data taken was "primarily customer business contact information, such as names and contact info, company attributes, and basic customer support case information", and that the incident was "isolated to our CRM platform." See our page on the Palo Alto Networks exposure.

The larger risk was secondary: any key or password a customer had pasted into a support case was now in the actor's hands, which is why the response focused on rotating credentials found in the data.

What this means for NHI governance

The Salesloft Drift breach is a non-human identity breach from end to end. After the GitHub foothold, every step used machine credentials: cloud access to Drift's AWS environment, OAuth tokens for customer integrations, and finally the keys and passwords inside CRM records. Victims' MFA and single sign-on were never tested, because the attacker arrived as an application they had already authorised.

The breach shows how SaaS-to-SaaS integrations concentrate risk. Each customer granted Drift a broad, long-lived connection to its Salesforce data, and Drift stored those grants for all customers in one environment. Compromising that vendor environment gave the attacker what McLellan described as access to tokens "for any Drift linked organization." Customers could not see how Drift protected those tokens, and few could readily list which integrations held standing access to their CRM. The Klue OAuth supply chain breach follows a similar pattern.

The second lesson is about secrets in the wrong place. The attacker was not mainly after sales data: it was after the credentials customers had put into support tickets. Secrets pasted into tickets inherit the third-party exposure of whatever system stores them. Cloudflare's rotation of 104 of its own tokens shows how quickly that adds up.

Recommendations

  • Inventory every connected app and integration token. Know which OAuth apps can reach Salesforce, Google Workspace and other SaaS platforms, who owns each and what scopes it holds. The SaaS-to-SaaS and OAuth App Governance Guide sets out how.
  • Reduce scopes and restrict where tokens can be used. Give integrations only the objects and permissions they need, and use IP restrictions or connected app policies so a stolen token cannot be used from anywhere on the internet.
  • Revoke and rotate when a vendor is breached. Treat every token connected to an affected integration as compromised, as GTIG advised, then rotate any credentials that appeared in data the integration could read. Challenges of Rotating NHIs explains why this needs planning in advance.
  • Keep secrets out of tickets and CRM records. Scan case text for secrets and redact them automatically. See the Secrets Management Guide.
  • Monitor integration behaviour. Alert on bulk exports, unusual queries and access from TOR or anonymising proxies by integration users.
  • Ask vendors how they store your tokens. Cover token storage and source control security in third-party reviews of any vendor with delegated access.

Frequently asked questions

What happened in the Salesloft Drift breach?

A threat actor tracked by Google as UNC6395 used stolen Salesloft Drift OAuth tokens between 8 and 18 August 2025 to export data from many organisations' Salesforce instances, then searched it for credentials.

How did attackers get the Drift OAuth tokens?

According to Salesloft and Mandiant, the actor accessed Salesloft's GitHub account between March and June 2025, then accessed Drift's AWS environment and obtained OAuth tokens for Drift customers' technology integrations. Salesloft has not said how the GitHub account was first compromised.

Is the Salesloft Drift breach the same as the ShinyHunters Salesforce attacks?

No. The ShinyHunters campaign used phone calls to persuade employees to connect malicious apps to Salesforce. The Drift campaign used tokens stolen from a vendor, with no employee involvement. Google said it had no compelling evidence linking UNC6395 to ShinyHunters.

ShinyHunters Salesforce data theft campaign 2025 · Palo Alto Networks Salesforce exposure · Klue OAuth supply chain breach · SaaS-to-SaaS and OAuth App Governance Guide · NHI breaches

How NHI Mgmt Group can help

OAuth integration tokens are some of the most powerful and least watched non-human identities in any SaaS estate. Our NHI Foundation Level Training Course helps teams inventory, own and govern these tokens alongside API keys, service accounts and other machine credentials.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org