Salesloft says hackers stole OAuth tokens from its Drift chat agent integration to conduct a Salesforce data theft campaign between August 8 and August 18
Update: Story updated with further information. — Hackers breached sales automation platform Salesloft to steal OAuth and refresh tokens …
BleepingComputer Lawrence Abrams
Related Coverage
- Drift/Salesforce Security Update Salesloft Trust Portal
- Widespread Data Theft Targets Salesforce Instances via Salesloft Drift Google Cloud Blog
- Salesforce data missing? It might be due to Salesloft breach, Google says The Register · Connor Jones
- Google warns 2.5B Gmail users to update passwords after hackers complete ‘successful intrusions’ New York Post · Taylor Herzlich
- Salesloft OAuth Breach via Drift AI Chat Agent Exposes Salesforce Customer Data The Hacker News
- Hundreds of Salesforce customer orgs hit in clever attack with potentially huge blast radius Help Net Security · Zeljka Zorz
- Google Reveals UNC6395's OAuth Token Theft in Salesforce Breach Hackread · Deeba Ahmed
- New Data Theft Campaign Targets Salesforce via Salesloft App Infosecurity · Phil Muncaster
- Widespread Data Theft Campaign Strikes Salesforce via Salesloft Drift CyberInsider · Bill Mann
- Salesloft Drift Hacked to Steal OAuth Tokens and Exfiltrate from Salesforce Corporate Instances Cyber Security News · Florence Nightingale
- Attackers steal data from Salesforce instances via compromised AI live chat tool CSO · Lucian Constantin
- Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks DataBreaches.Net
- Hackers steal data from Salesforce instances in widespread campaign TechCentral.ie
- Hundreds of Salesforce customers impacted by attack spree linked to third-party AI agent CyberScoop · Matt Kapko
- An actor we are tracking as UNC6395 is targeting Salesforce customer instances through compromised OAuth tokens associated with the Salesloft Drift third-party application. … John Hultquist
Discussion
-
@new23d
@new23d
on bluesky
Another short-lived credential leak causes widespread data theft. Here at @chasersystems.bsky.social we're researching & prototyping practical second-factor methods for service account style usage. — cloud.google.com/blog/topics/ ...
-
@campuscodi.risky.biz
Catalin Cimpanu
on bluesky
A threat actor (UNC6395) is accessing Salesforce accounts and data through the Salesloft Drift AI chat agent — cloud.google.com/blog/topics/ ...