• News/
  • https://www.bleepingcomputer.com/news/security/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks/

ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks

BleepingComputer
·
Lawrence Abrams
·
Published Sep 17, 2025
·
Updated

The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens. For the past year, the threat actors have been targeting Salesforce customers in data theft attacks using social engineering and malicious OAuth applications to breach Salesforce instances and download data. The stolen data is then used to extort companies into paying a ransom to prevent the data from being publicly leaked. These attacks have been claimed by threat actors stating they are part of the ShinyHunters, Scattered Spider, and Lapsus$ extortion groups, now calling themselves "Scattered Lapsus$ Hunters." Google tracks this activity as UNC6040 and UNC6395. In March, one of the threat actors breached Salesloft's GitHub repository, which contained the private source code for the company. ShinyHunters told BleepingComputer that the threat actors used the TruffleHog security tool to scan the source code for secrets, which resulted in the finding of OAuth tokens for the Salesloft Drift and the Drift Email platforms. Salesloft Drift is a third-party platform that connects the Drift AI chat agent with a Salesforce instance, allowing organizations to sync conversations, leads, and support cases into their CRM. Drift Email is used to manage email replies and organize CRM and marketing automation databases. Using these stolen Drift OAuth tokens, ShinyHunters told BleepingComputer that the threat actors stole approximately ...

Read full article

Affected Software

2 affected components
Salesforce Salesforce
Salesloft Drift
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the claim by the ShinyHunters group about stealing 1.5 billion records from Salesforce through compromised Drift OAuth tokens.

2

What security implications are discussed in the article?

The article highlights significant security risks associated with OAuth token vulnerabilities that can lead to data breaches in cloud-based applications.

3

What companies are primarily affected by this security incident?

Approximately 760 companies using Salesforce and associated integration with Salesloft Drift have been affected by the breach.

4

What kind of data was reportedly stolen?

The stolen data includes over 1.5 billion Salesforce records, which may contain sensitive customer and corporate information.

5

What methods did the attackers use to carry out the breach?

The attackers exploited compromised OAuth tokens from Salesloft Drift to gain unauthorized access to Salesforce records.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203