The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens. For the past year, the threat actors have been targeting Salesforce customers in data theft attacks using social engineering and malicious OAuth applications to breach Salesforce instances and download data. The stolen data is then used to extort companies into paying a ransom to prevent the data from being publicly leaked. These attacks have been claimed by threat actors stating they are part of the ShinyHunters, Scattered Spider, and Lapsus$ extortion groups, now calling themselves "Scattered Lapsus$ Hunters." Google tracks this activity as UNC6040 and UNC6395. In March, one of the threat actors breached Salesloft's GitHub repository, which contained the private source code for the company. ShinyHunters told BleepingComputer that the threat actors used the TruffleHog security tool to scan the source code for secrets, which resulted in the finding of OAuth tokens for the Salesloft Drift and the Drift Email platforms. Salesloft Drift is a third-party platform that connects the Drift AI chat agent with a Salesforce instance, allowing organizations to sync conversations, leads, and support cases into their CRM. Drift Email is used to manage email replies and organize CRM and marketing automation databases. Using these stolen Drift OAuth tokens, ShinyHunters told BleepingComputer that the threat actors stole approximately ...
ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks
BleepingComputer
·Lawrence Abrams
·Published Sep 17, 2025
·Updated
Affected Software
2 affected components
Salesforce Salesforce
Salesloft Drift
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the claim by the ShinyHunters group about stealing 1.5 billion records from Salesforce through compromised Drift OAuth tokens.
2
What security implications are discussed in the article?
The article highlights significant security risks associated with OAuth token vulnerabilities that can lead to data breaches in cloud-based applications.
3
What companies are primarily affected by this security incident?
Approximately 760 companies using Salesforce and associated integration with Salesloft Drift have been affected by the breach.
4
What kind of data was reportedly stolen?
The stolen data includes over 1.5 billion Salesforce records, which may contain sensitive customer and corporate information.
5
What methods did the attackers use to carry out the breach?
The attackers exploited compromised OAuth tokens from Salesloft Drift to gain unauthorized access to Salesforce records.