← CyberArk

2025 cyberark — Salesloft/Drift OAuth supply chain; Salesforce CRM data accessed (2025-09-04)

2025 Unknown records affected Share on X

Data compromised

Typically names, business emails, phones, employer metadata, and support-case subjects or correspondence snippets held in Salesforce—per each organization’s customer notice.

Technical writeup

In August–September 2025, multiple vendors publicly confirmed that threat activity—widely reported in connection with compromised OAuth tokens for the Salesloft Drift integration with Salesforce—enabled unauthorized queries/export-style access to limited Salesforce-held business contact and customer-support case material. Vendor statements routinely emphasized that core product clouds and unrelated infrastructure were not impacted; exact fields and scope differ by company.

Root cause

Abuse of trusted third-party Salesforce OAuth integration (Salesloft Drift supply chain) per vendor disclosures and industry reporting (UNC6395 / GRUB1 narratives in wider coverage).

References