2025 cyberark — Salesloft/Drift OAuth supply chain; Salesforce CRM data accessed (2025-09-04)
Data compromised
Typically names, business emails, phones, employer metadata, and support-case subjects or correspondence snippets held in Salesforce—per each organization’s customer notice.
Technical writeup
In August–September 2025, multiple vendors publicly confirmed that threat activity—widely reported in connection with compromised OAuth tokens for the Salesloft Drift integration with Salesforce—enabled unauthorized queries/export-style access to limited Salesforce-held business contact and customer-support case material. Vendor statements routinely emphasized that core product clouds and unrelated infrastructure were not impacted; exact fields and scope differ by company.
Root cause
Abuse of trusted third-party Salesforce OAuth integration (Salesloft Drift supply chain) per vendor disclosures and industry reporting (UNC6395 / GRUB1 narratives in wider coverage).
References
- https://www.cyberark.com/resources/blog/salesloft-drift-incident-overview-and-cyberarks-response
- https://www.nudgesecurity.com/post/breach-of-salesloft-drift-oauth-tokens-leads-to-salesforce-data-theft
- https://driftbreach.com/
- https://www.finra.org/rules-guidance/guidance/salesloft-drift-AI-supply-chain-attack
- https://thehackernews.com/2025/08/salesloft-oauth-breach-via-drift-ai.html