/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Salesloft says hackers stole OAuth tokens from its Drift chat agent integration to conduct a Salesforce data theft campaign between August 8 and August 18

Update: Story updated with further information.  —  Hackers breached sales automation platform Salesloft to steal OAuth and refresh tokens …

BleepingComputer Lawrence Abrams

Context & Ripple Effects

This report identifies a SaaS-integration route into Salesforce environments: credentials associated with Salesloft's Drift connection, rather than a disclosed direct Salesforce platform compromise. It sits alongside earlier reporting of Salesforce-focused intrusions involving loosely affiliated Com actors, suggesting customer-data systems had already become a high-value target surface.

The incident became a broader customer-impact story as Cloudflare disclosed access to its Salesforce support and case-management instance, followed by claims of a much larger campaign using the same compromised integration credentials. The important arc is the reuse of delegated access across many organizations.

First-order effects

  • Organizations that connected Drift to Salesforce may need to treat the affected OAuth and refresh tokens as compromised, investigate Salesforce access, and rotate or revoke the relevant credentials.
  • Salesloft and its customers face an immediate trust and incident-response burden because a third-party integration's delegated permissions were used to reach customer CRM data.

Second-order effects

  • Other Salesforce-connected vendors and customers are likely to review OAuth grants, token lifetimes, and the scope of app permissions; the Cloudflare disclosure shows the impact was not confined to Salesloft itself.
  • Security teams will increasingly evaluate business-software integrations as supply-chain access paths, not merely as standalone vendor applications, raising the cost of broadly privileged persistent tokens.

Third-order effects

  • If comparable incidents continue, CRM ecosystems may shift toward narrower, more time-limited delegated access and stronger monitoring of cross-tenant application activity, though the corpus does not establish which controls vendors will adopt.
  • The later Gainsight-linked theft of Salesforce-stored data from more than 200 companies indicates that third-party support and workflow connections can become a recurring concentration risk around shared customer-data platforms.

The trend: Enterprise SaaS security is moving toward scrutiny of the delegated OAuth links that connect workflow tools to systems of record, as those links concentrate access across many customers.

Discussion

  • @new23d @new23d on bluesky
    Another short-lived credential leak causes widespread data theft.  Here at @chasersystems.bsky.social we're researching & prototyping practical second-factor methods for service account style usage.  —  cloud.google.com/blog/topics/ ...
  • @campuscodi.risky.biz Catalin Cimpanu on bluesky
    A threat actor (UNC6395) is accessing Salesforce accounts and data through the Salesloft Drift AI chat agent  —  cloud.google.com/blog/topics/ ...