Salesloft says hackers stole OAuth tokens from its Drift chat agent integration to conduct a Salesforce data theft campaign between August 8 and August 18
Update: Story updated with further information. — Hackers breached sales automation platform Salesloft to steal OAuth and refresh tokens …
Context & Ripple Effects
This report identifies a SaaS-integration route into Salesforce environments: credentials associated with Salesloft's Drift connection, rather than a disclosed direct Salesforce platform compromise. It sits alongside earlier reporting of Salesforce-focused intrusions involving loosely affiliated Com actors, suggesting customer-data systems had already become a high-value target surface.
The incident became a broader customer-impact story as Cloudflare disclosed access to its Salesforce support and case-management instance, followed by claims of a much larger campaign using the same compromised integration credentials. The important arc is the reuse of delegated access across many organizations.
First-order effects
- Organizations that connected Drift to Salesforce may need to treat the affected OAuth and refresh tokens as compromised, investigate Salesforce access, and rotate or revoke the relevant credentials.
- Salesloft and its customers face an immediate trust and incident-response burden because a third-party integration's delegated permissions were used to reach customer CRM data.
Second-order effects
- Other Salesforce-connected vendors and customers are likely to review OAuth grants, token lifetimes, and the scope of app permissions; the Cloudflare disclosure shows the impact was not confined to Salesloft itself.
- Security teams will increasingly evaluate business-software integrations as supply-chain access paths, not merely as standalone vendor applications, raising the cost of broadly privileged persistent tokens.
Third-order effects
- If comparable incidents continue, CRM ecosystems may shift toward narrower, more time-limited delegated access and stronger monitoring of cross-tenant application activity, though the corpus does not establish which controls vendors will adopt.
- The later Gainsight-linked theft of Salesforce-stored data from more than 200 companies indicates that third-party support and workflow connections can become a recurring concentration risk around shared customer-data platforms.
The trend: Enterprise SaaS security is moving toward scrutiny of the delegated OAuth links that connect workflow tools to systems of record, as those links concentrate access across many customers.