← Salesloft

2025 Salesloft (Drift chat) / Salesforce — OAuth token theft (UNC6395); not Drift Protocol crypto

2025 Unknown records affected Share on X

Data compromised

Varies by tenant: CRM records and support-case content; harvested secrets in tickets per GTIG; not a single uniform consumer row count

Technical writeup

Scope note: this entry is Salesloft’s Drift conversational/Salesforce integration product—not the Solana DeFi “Drift Protocol” exchange (see drift-protocol2026). Between approximately August 8 and August 18, 2025, the threat cluster tracked as UNC6395 used compromised OAuth tokens associated with the Salesloft Drift third-party application to access many customers’ Salesforce instances, systematically exporting large volumes of CRM data (e.g., Accounts, Cases, Contacts, Opportunities, Users) and hunting embedded secrets—Google Threat Intelligence Group cited interest in AWS access keys, passwords, and Snowflake-related tokens. On August 20, 2025, Salesloft and Salesforce revoked active Drift OAuth tokens and Salesforce removed Drift from AppExchange pending review; the issue was framed as integration/third-party compromise rather than a core Salesforce platform flaw. An August 28, 2025 update broadened guidance: tokens beyond Salesforce-integrated Drift could be in scope, and Google disclosed compromise of “Drift Email” OAuth tokens used against a small number of Google Workspace accounts configured for that integration—Google revoked those tokens and disabled the integration. Industry roundups cited on the order of 700–750+ downstream organizations affected across sectors. The incident remained a reference point in 2026 for credential-reuse and supply-chain follow-ons (e.g., BPO and Zendesk-adjacent narratives).

Root cause

Compromised OAuth tokens for Salesloft Drift (and related Drift integrations); third-party SaaS supply chain

References