CIO Brief: Every Integration Is a Trust Relationship
Retrospective: this article looks back at events from August 2025, written in 2026 with the benefit of hindsight.
The short version: In August 2025, attackers stole access tokens from Salesloft's Drift chatbot integration and used them to download data from hundreds of companies' Salesforce systems — then searched that data for passwords and cloud keys to break into more systems.
Why integrations are trust relationships
Every time you connect one cloud app to another — CRM to chatbot, email to scheduling tool — you give a vendor a token that can read (and sometimes change) your data. That token often bypasses your login security entirely. If the vendor is compromised, your data is too.
The business impact
- Mass data theft from core business systems.
- Secondary breaches when stolen data contains passwords or keys.
- Dependence on vendors you may barely remember connecting.
Questions to ask your team
- How many third-party apps are connected to our CRM, email and file systems?
- What can each one access, and do we still use it?
- Do employees store passwords or keys in tickets, notes or CRM records?
- Would we notice if an integration suddenly exported all our customer data?
What good looks like
An inventory of integrations with owners, least-privilege access, unused integrations removed, secrets kept out of business records, and monitoring for bulk data access.
The decision
Ask for a list of every app connected to your CRM and Microsoft 365. Remove what isn't needed — every connection you remove is one less trust relationship to defend.
- Salesloft Drift (Aug 2025): Stolen OAuth Tokens Hit Hundreds of Salesforce Tenants Incident Teardowns
- How to Audit SaaS-to-SaaS OAuth Integrations and Token Scopes How-To & Hardening
- Detecting SaaS OAuth Token Theft: Sentinel and GuardDuty Detections Detection & Response