Update: Story updated with further information. Hackers breached sales automation platform Salesloft to steal OAuth and refresh tokens from its Drift chat agent integration with Salesforce to pivot to customer environments and exfiltrate data. Salesloft's SalesDrift is a third-party platform that connects the Drift AI chat agent with a Salesforce instance, allowing organizations to sync conversations, leads, and support cases into their CRM. According to Salesloft, threat actors obtained Drift OAuth and refresh tokens used for its Salesforce integration, and used them to conduct a Salesforce data theft campaign between August 8 and August 18, 2025. "Initial findings have shown that the actor's primary objective was to steal credentials, specifically focusing on sensitive information like AWS access keys, passwords, and Snowflake-related access tokens," reads a Salesloft advisory. "We have determined that this incident did not impact customers who do not use our Drift-Salesforce integration. Based on our ongoing investigation, we do not see evidence of ongoing malicious activity related to this incident." In coordination with Salesforce, Salesloft revoked all active access and refresh tokens for the Drift application, requiring customers to re-authenticate with their Salesforce instances. To reauthenticate, admins should go to Settings > Integrations > Salesforce, disconnect the integration, and then reconnect with valid Salesforce credentials. Google's Threat Intelligence te...
Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks
BleepingComputer
·Lawrence Abrams
·Published Aug 26, 2025
·Updated
Affected Software
2 affected components
Salesloft SalesDrift
Salesloft Salesforce
Frequently Asked Questions
1
What was the main issue discussed in the article?
The article discusses the breach of Salesloft where hackers stole OAuth tokens to access Salesforce data.
2
What security implications are highlighted in the incident?
The breach raises concerns about the security of OAuth token storage and the potential for data exfiltration from customer environments.
3
Which platforms were specifically mentioned as affected in the breach?
The affected platforms include Salesloft's SalesDrift and Salesforce integrations.
4
How did the attackers utilize the stolen tokens?
The attackers used the stolen OAuth and refresh tokens to pivot into customer environments to exfiltrate data.
5
Is there any mention of actions being taken by Salesloft in response to the breach?
The article does not specify any immediate actions taken by Salesloft in response to the breach.