Multi-CloudCIO BriefingsRetrospectives

CIO Brief: Every Integration Is a Trust Relationship

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2025, written in 2026 with the benefit of hindsight.

The short version: In August 2025, attackers stole access tokens from Salesloft's Drift chatbot integration and used them to download data from hundreds of companies' Salesforce systems — then searched that data for passwords and cloud keys to break into more systems.

Why integrations are trust relationships

Every time you connect one cloud app to another — CRM to chatbot, email to scheduling tool — you give a vendor a token that can read (and sometimes change) your data. That token often bypasses your login security entirely. If the vendor is compromised, your data is too.

The business impact

  • Mass data theft from core business systems.
  • Secondary breaches when stolen data contains passwords or keys.
  • Dependence on vendors you may barely remember connecting.

Questions to ask your team

  • How many third-party apps are connected to our CRM, email and file systems?
  • What can each one access, and do we still use it?
  • Do employees store passwords or keys in tickets, notes or CRM records?
  • Would we notice if an integration suddenly exported all our customer data?

What good looks like

An inventory of integrations with owners, least-privilege access, unused integrations removed, secrets kept out of business records, and monitoring for bulk data access.

The decision

Ask for a list of every app connected to your CRM and Microsoft 365. Remove what isn't needed — every connection you remove is one less trust relationship to defend.

salesloft drift breach impactSalesloft Drift OAuth2025

More on this story