• News/
  • https://www.bleepingcomputer.com/news/security/salesloft-march-github-repo-breach-led-to-salesforce-data-theft-attacks/

Salesloft: March GitHub repo breach led to Salesforce data theft attacks

BleepingComputer
·
Bill Toulas
·
Published Sep 8, 2025
·
Updated

Salesloft says attackers first breached its GitHub account in March, leading to the theft of Drift OAuth tokens later used in widespread Salesforce data theft attacks in August. Salesloft is a widely used sales engagement platform that helps companies manage outreach and customer communications. Its Drift platform is a conversational marketing tool that integrates chatbots and automation into sales pipelines, including integrations with platforms like Salesforce. The two have been at the center of a major supply-chain style breach first disclosed in late August, with Google's Threat Intelligence Group attributing the attacks to UNC6395. However, BleepingComputer has learned that the ShinyHunters extortion gang and threat actors claiming to be Scattered Spider were involved in the Salesloft Drift attacks, in addition to the previous Salesforce data theft attacks. Salesloft first disclosed a security issue in the Drift application on August 21 and revealed more details about malicious exploitation of the OAuth tokens five days later. This has led to widespread Salesforce data theft attacks on Salesloft customers, including Google, Zscaler, Cloudflare, Workiva, Tenable, JFrog, Bugcrowd, Proofpoint, Palo Alto Networks, and the list is still growing. In the Salesloft data theft attacks, the threat actors primarily focused on stealing support cases from Salesforce instances, which were then used to harvest credentials, authentication tokens, and other secrets shared in the support...

Read full article

Affected Software

2 affected components
Salesloft Drift
Salesloft Sales Engagement Platform
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a breach of Salesloft's GitHub account that led to data theft incidents involving Salesforce.

2

What security implications are discussed in the article?

The article highlights how compromised OAuth tokens can facilitate unauthorized access to sensitive data.

3

What products or software are affected by this breach?

The affected products mentioned are the Salesloft platform and Drift OAuth tokens.

4

When did the initial breach of Salesloft's GitHub account occur?

The initial breach occurred in March.

5

How did the breach impact Salesforce users?

The stolen tokens were leveraged in widespread data theft attacks against Salesforce users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203