2025 Matillion — Salesloft Drift OAuth / Salesforce tenant exposure (supply-chain campaign)
Data compromised
Salesforce CRM objects, billing metadata, and hub-related technical identifiers per Matillion disclosure
Technical writeup
Matillion publicly confirmed compromise of credentials linking the Salesloft Drift chat integration to its Salesforce tenant, part of a broader August–September 2025 supply-chain wave in which stolen OAuth tokens let actors run SOQL-style queries against customer Salesforce orgs. Matillion’s Trust Center stated production analytics products (Data Productivity Cloud, Maia, Matillion ETL) were isolated and unaffected, while Salesforce-held fields could include hub login IP metadata, role labels, contract values, and partial card-related billing metadata mirrored from Recurly workflows; the vendor also scanned support cases for pasted secrets.
Root cause
Third-party Salesloft Drift integration compromise and abused Salesforce OAuth trust (UNC6395 / GRUB1 campaign per industry and FINRA-style alerts)