• News/
  • https://www.bleepingcomputer.com/news/security/google-warns-salesloft-breach-impacted-some-workspace-accounts/

Google warns Salesloft breach impacted some Workspace accounts

BleepingComputer
·
Lawrence Abrams
·
Published Aug 28, 2025
·
Updated

Google now reports that the Salesloft Drift breach is larger than initially thought, warning that attackers also used stolen OAuth tokens to access a small number of Google Workspace email accounts in addition to stealing data from Salesforce instances. "Based on new information identified by GTIG, the scope of this compromise is not exclusive to the Salesforce integration with Salesloft Drift and impacts other integrations,' warns Google. "We now advise all Salesloft Drift customers to treat any and all authentication tokens stored in or connected to the Drift platform as potentially compromised." The campaign, tracked by Google Threat Intelligence (Mandiant) as UNC6395, was first disclosed on August 26 after attackers stole OAuth tokens for Salesloft's Drift AI chat integration with Salesforce. The threat actors used these tokens to gain access to customer Salesforce instances, where they executed queries against Salesforce objects, including the Cases, Accounts, Users, and Opportunities tables. This data allowed the attackers to scan customer support tickets and messages for sensitive information, such as AWS access keys, Snowflake tokens, and passwords that could be used to breach further cloud accounts, likely for future extortion. In an update published today, Google confirmed that the compromise was more significant than initially believed and not limited to Salesforce integrations. The investigation revealed that OAuth tokens for the "Drift Email" integration were al...

Read full article

Affected Software

2 affected components
Salesloft Drift
Google Workspace
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What incident prompted Google's warning about Workspace accounts?

The warning was triggered by the Salesloft Drift breach, which has affected some Google Workspace accounts.

2

What type of access was gained by attackers in the Salesloft breach?

Attackers used stolen OAuth tokens to access a small number of Google Workspace email accounts.

3

What additional data was compromised in the Salesloft breach?

In addition to Google Workspace emails, data was stolen from Salesforce instances.

4

Who reported the new information regarding the Salesloft breach?

The new information regarding the breach was reported by Google's Threat Analysis Group (GTIG).

5

When was the breach and its implications reported by Google?

Google reported the breach and its implications on August 28, 2025.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203