Salesloft Drift (Aug 2025): Stolen OAuth Tokens Hit Hundreds of Salesforce Tenants
Facts in this article were checked against the sources listed below as of Oct 5, 2026.
Retrospective: this article looks back at events from August 2025, written in 2026 with the benefit of hindsight.
On August 26, 2025, Google Threat Intelligence Group published a report on a widespread data theft campaign by a threat actor it tracks as UNC6395. The actor used compromised OAuth tokens for Salesloft Drift — an AI chat and sales engagement integration — to access customers' Salesforce instances. Malicious activity was observed between August 8 and at least August 18, and data was exfiltrated from hundreds of organizations, including many technology and security companies that later published their own disclosures.
- Integration tokens stolenThe actor obtains OAuth tokens used by the Salesloft Drift chatbot integration with Salesforce.
- MFA bypassedValid OAuth tokens let the actor query Salesforce without signing in as a user.
- Bulk exportBetween August 8 and at least August 18, 2025, large volumes of Salesforce data are exfiltrated from many organizations.
- Secret huntingThe actor searches stolen records for AWS access keys, passwords and Snowflake-related tokens.
- ContainmentSalesloft and Salesforce revoke all Drift tokens; Google Threat Intelligence publishes its report on August 26.
The attacker never needed a user's password or MFA code. It used the integration's own trusted access.
What happened
Drift connected to customers' Salesforce environments through OAuth, the standard way SaaS applications are authorized to act on each other's data. UNC6395 obtained those tokens and used them to run queries and export records — accounts, contacts, cases and users — at scale.
The actor's primary goal, according to Google, was credential theft: it searched the stolen data for AWS access keys, passwords and Snowflake-related access tokens that customers had stored in support cases, notes and other fields. Those secrets could open doors far beyond Salesforce.
Salesloft and Salesforce revoked all active access and refresh tokens for the Drift application, requiring administrators to re-authenticate the integration. Reporting later indicated that some Google Workspace accounts connected through Drift were also accessed, and subsequent investigations traced the compromise back to earlier intrusions into Salesloft's environment.
Why it mattered
SaaS-to-SaaS integrations are a major, under-monitored attack surface. Organizations connect dozens of apps to their CRM, email and file platforms. Each connection holds a token that can read — and sometimes change — data.
OAuth tokens bypass identity controls. SSO, MFA and Conditional Access protect user sign-ins. A stolen integration token sidesteps all of them.
Secrets in business records multiply the damage. API keys pasted into support tickets turned a CRM data theft into a potential cloud compromise.
One vendor, hundreds of victims. As with MOVEit and Snowflake, a single point of compromise produced a wave of disclosures.
What to do now
- Inventory connected apps on every major SaaS platform. In Salesforce, review Connected Apps and OAuth usage; in Microsoft 365, review enterprise applications and use Defender for Cloud Apps app governance; in Google Workspace, review app access control. SaaS security posture tools can consolidate the view.
- Record what each integration can do. Vendor, business owner, scopes (read all, write, admin), the user or integration account the token belongs to, and last use.
- Remove what isn't used. Integrations idle for 90 days should go.
- Restrict scopes and tokens. Ask vendors for least-privilege scopes. In Salesforce, use connected app policies such as admin-approved users only, IP restrictions and refresh token lifetime limits. In Entra ID, restrict application access to specific mailboxes or sites where supported.
- Use dedicated integration users with restricted profiles, rather than tokens tied to administrators.
- Get secrets out of business data. Scan CRM records, support tickets and notes for credentials, rotate anything found and give support teams a secure way to receive secrets that doesn't store them in tickets.
- Stream SaaS audit logs — for example Salesforce Event Monitoring and Microsoft 365 audit logs — into your SIEM.
- Prepare a vendor-token playbook: revoke tokens, assess data accessed, search exported data for secrets, rotate and notify.
How to detect integration token abuse
- API calls from unexpected IP addresses for a connected app, compared against the vendor's known ranges and your baseline.
- Bulk queries and exports on objects such as Account, Contact, Case and User.
- Searches for secret patterns — queries containing strings like "AKIA," "password," "secret" or "token."
- Deleted query jobs or export records soon after they run, which may indicate an attempt to hide activity.
- Spikes in API usage by a connected app.
- Service principal sign-ins in Entra ID from new IP addresses for Microsoft 365–connected apps.
Common mistakes
- Forgetting integrations exist once they're connected.
- Granting broad scopes because the vendor requested them.
- Storing secrets in tickets and CRM notes.
- Monitoring user sign-ins but not API activity from integrations.
A simple integration review template
For each connected application, record and review: the vendor and business owner; the data it can access and the actions it can take; whether it acts as a specific integration user or a person; token lifetime and whether refresh tokens are restricted; network restrictions; when it was last used; and the vendor's security attestations and incident notification commitments. Review high-access integrations quarterly and remove anything without an owner. When a vendor reports a breach, this record tells you in minutes what's at risk and which tokens to revoke.
Why secrets end up in CRM and tickets
Support teams often ask customers to share credentials, API keys or configuration files to troubleshoot problems. Engineers paste keys into tickets for convenience. Over time, CRM and ticketing systems quietly become secret stores — without the encryption, access control or rotation of a real vault. Give support and engineering teams a secure channel for sharing secrets, set expectations with customers, and scan regularly for keys in tickets and notes.
Questions for leadership
- How many third-party apps are connected to our CRM, email and file platforms?
- What can each one access, and do we still use it?
- Are passwords or keys stored in our support tickets or CRM records?
Key takeaways
- UNC6395 used stolen Salesloft Drift OAuth tokens to export data from hundreds of Salesforce instances.
- The actor hunted for AWS keys, passwords and Snowflake tokens in stolen records.
- OAuth integrations bypass MFA; inventory them, limit scopes and monitor API activity.
- Keep secrets out of business records, and prepare to revoke vendor tokens quickly.
Sources
- How to Audit SaaS-to-SaaS OAuth Integrations and Token Scopes How-To & Hardening
- Detecting SaaS OAuth Token Theft: Sentinel and GuardDuty Detections Detection & Response
- CIO Brief: Every Integration Is a Trust Relationship CIO Briefings