/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

ShinyHunters claims it stole 1.5B+ Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens; a source says the numbers are accurate

The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.

BleepingComputer Lawrence Abrams

Context & Ripple Effects

Salesloft previously said that OAuth tokens tied to its Drift chat-agent integration were used in a Salesforce data-theft campaign during August. This report turns that earlier disclosure of compromised Drift OAuth tokens into a much larger claimed victim and record count.

The allegation also fits ShinyHunters’ established pattern of publicizing and monetizing purported large-scale data hauls, including its earlier claims of hundreds of millions of stolen records. A source backing the figures raises the stakes, though the group’s claims remain distinct from public confirmation by every affected company.

First-order effects

  • Salesforce customers potentially reached through the compromised integration face urgent exposure assessment: determining whether their instance was accessed, what records were taken, and whether customer or employee notifications are required.
  • Salesloft and Salesforce face immediate pressure from customers to explain the integration’s access path, token controls, and the scope of the affected tenant population; ShinyHunters gains added leverage for extortion or data-release threats.

Second-order effects

  • Other SaaS vendors and enterprise buyers will scrutinize OAuth-connected apps with broad CRM permissions, likely accelerating token revocation, integration audits, and tighter limits on third-party access.
  • The incident makes a vendor integration—not just a company’s own Salesforce configuration—a focal point of procurement and security review, increasing the cost of proving controls for CRM-adjacent software providers.

Third-order effects

  • If similar campaigns persist, enterprise identity security will shift further from protecting individual applications toward continuously governing delegated access across SaaS supply chains, especially long-lived OAuth credentials.
  • The scale alleged here could strengthen the case for customers and regulators to demand clearer breach attribution and shared accountability among cloud platforms, integration vendors, and affected enterprises.

The trend: This is part of the broader shift from single-company breaches toward identity- and integration-layer attacks that can expose many enterprises through one trusted SaaS connection.

Discussion

  • r/technews r on reddit
    ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks
  • r/technology r on reddit
    ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks