Salesloft says attackers first breached its GitHub account in March, leading to the theft of Drift OAuth tokens later used in widespread Salesforce data theft attacks in August. Salesloft is a widely used sales engagement platform that helps companies manage outreach and customer communications. Its Drift platform is a conversational marketing tool that integrates chatbots and automation into sales pipelines, including integrations with platforms like Salesforce. The two have been at the center of a major supply-chain style breach first disclosed in late August, with Google's Threat Intelligence Group attributing the attacks to UNC6395. However, BleepingComputer has learned that the ShinyHunters extortion gang and threat actors claiming to be Scattered Spider were involved in the Salesloft Drift attacks, in addition to the previous Salesforce data theft attacks. Salesloft first disclosed a security issue in the Drift application on August 21 and revealed more details about malicious exploitation of the OAuth tokens five days later. This has led to widespread Salesforce data theft attacks on Salesloft customers, including Google, Zscaler, Cloudflare, Workiva, Tenable, JFrog, Bugcrowd, Proofpoint, Palo Alto Networks, and the list is still growing. In the Salesloft data theft attacks, the threat actors primarily focused on stealing support cases from Salesforce instances, which were then used to harvest credentials, authentication tokens, and other secrets shared in the support...
Salesloft: March GitHub repo breach led to Salesforce data theft attacks
BleepingComputer
·Bill Toulas
·Published Sep 8, 2025
·Updated
Affected Software
2 affected components
Salesloft Drift
Salesloft Sales Engagement Platform
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a breach of Salesloft's GitHub account that led to data theft incidents involving Salesforce.
2
What security implications are discussed in the article?
The article highlights how compromised OAuth tokens can facilitate unauthorized access to sensitive data.
3
What products or software are affected by this breach?
The affected products mentioned are the Salesloft platform and Drift OAuth tokens.
4
When did the initial breach of Salesloft's GitHub account occur?
The initial breach occurred in March.
5
How did the breach impact Salesforce users?
The stolen tokens were leveraged in widespread data theft attacks against Salesforce users.