• News/
  • https://www.bleepingcomputer.com/news/security/salesloft-breached-to-steal-oauth-tokens-for-salesforce-data-theft-attacks/

Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks

BleepingComputer
·
Lawrence Abrams
·
Published Aug 26, 2025
·
Updated

Update: Story updated with further information. Hackers breached sales automation platform Salesloft to steal OAuth and refresh tokens from its Drift chat agent integration with Salesforce to pivot to customer environments and exfiltrate data. Salesloft's SalesDrift is a third-party platform that connects the Drift AI chat agent with a Salesforce instance, allowing organizations to sync conversations, leads, and support cases into their CRM. According to Salesloft, threat actors obtained Drift OAuth and refresh tokens used for its Salesforce integration, and used them to conduct a Salesforce data theft campaign between August 8 and August 18, 2025. "Initial findings have shown that the actor's primary objective was to steal credentials, specifically focusing on sensitive information like AWS access keys, passwords, and Snowflake-related access tokens," reads a Salesloft advisory. "We have determined that this incident did not impact customers who do not use our Drift-Salesforce integration. Based on our ongoing investigation, we do not see evidence of ongoing malicious activity related to this incident." In coordination with Salesforce, Salesloft revoked all active access and refresh tokens for the Drift application, requiring customers to re-authenticate with their Salesforce instances. To reauthenticate, admins should go to Settings > Integrations > Salesforce, disconnect the integration, and then reconnect with valid Salesforce credentials. Google's Threat Intelligence te...

Read full article

Affected Software

2 affected components
Salesloft SalesDrift
Salesloft Salesforce
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What was the main issue discussed in the article?

The article discusses the breach of Salesloft where hackers stole OAuth tokens to access Salesforce data.

2

What security implications are highlighted in the incident?

The breach raises concerns about the security of OAuth token storage and the potential for data exfiltration from customer environments.

3

Which platforms were specifically mentioned as affected in the breach?

The affected platforms include Salesloft's SalesDrift and Salesforce integrations.

4

How did the attackers utilize the stolen tokens?

The attackers used the stolen OAuth and refresh tokens to pivot into customer environments to exfiltrate data.

5

Is there any mention of actions being taken by Salesloft in response to the breach?

The article does not specify any immediate actions taken by Salesloft in response to the breach.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203