ShinyHunters claims it stole 1.5B+ Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens; a source says the numbers are accurate
The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.
Context & Ripple Effects
Salesloft previously said that OAuth tokens tied to its Drift chat-agent integration were used in a Salesforce data-theft campaign during August. This report turns that earlier disclosure of compromised Drift OAuth tokens into a much larger claimed victim and record count.
The allegation also fits ShinyHunters’ established pattern of publicizing and monetizing purported large-scale data hauls, including its earlier claims of hundreds of millions of stolen records. A source backing the figures raises the stakes, though the group’s claims remain distinct from public confirmation by every affected company.
First-order effects
- Salesforce customers potentially reached through the compromised integration face urgent exposure assessment: determining whether their instance was accessed, what records were taken, and whether customer or employee notifications are required.
- Salesloft and Salesforce face immediate pressure from customers to explain the integration’s access path, token controls, and the scope of the affected tenant population; ShinyHunters gains added leverage for extortion or data-release threats.
Second-order effects
- Other SaaS vendors and enterprise buyers will scrutinize OAuth-connected apps with broad CRM permissions, likely accelerating token revocation, integration audits, and tighter limits on third-party access.
- The incident makes a vendor integration—not just a company’s own Salesforce configuration—a focal point of procurement and security review, increasing the cost of proving controls for CRM-adjacent software providers.
Third-order effects
- If similar campaigns persist, enterprise identity security will shift further from protecting individual applications toward continuously governing delegated access across SaaS supply chains, especially long-lived OAuth credentials.
- The scale alleged here could strengthen the case for customers and regulators to demand clearer breach attribution and shared accountability among cloud platforms, integration vendors, and affected enterprises.
The trend: This is part of the broader shift from single-company breaches toward identity- and integration-layer attacks that can expose many enterprises through one trusted SaaS connection.