• News/
  • https://www.theregister.com/2025/08/27/salesforce_salesloft_breach/

Google links Salesforce data thefts to Salesloft breach

The Register
·
Connor Jones
·
Published Aug 27, 2025
·
Updated

UPDATE Google says a recent spate of Salesforce-related breaches was caused by attackers stealing OAuth tokens from the third-party Salesloft Drift app. Drift is used for automating sales processes, and it integrates with Salesforce databases, pulling relevant information such as leads and contact details into the platform to help coordinate pitches. Crucially, the campaign is being treated separately from the attacks on high-profile organizations – including Google itself – that also involved Salesforce data thefts. Attacks on the likes of Allianz Life, Workday, Qantas, LVMH brands, and more have been widely reported over the summer, but aren't thought to be linked to the Salesloft compromise. Instead, these incidents have widely been attributed to and claimed by the ShinyHunters group (UNC6240). Google says there isn't enough evidence to suggest the same attackers are behind the Salesloft incidents. While Salesforce customers have been targeted since May, it's believed these were more a blend of social engineering and stolen credentials, whereas the Salesloft attacks saw attackers steal Drift OAuth tokens to access Salesforce databases. Neither of the advisories from Salesloft or Google Threat Intelligence Group (GTIG) this week detailed exactly how the attacks transpired, or how the tokens were stolen, but we know they all took place between August 8 and 18. Salesloft said: "Initial findings have shown that the actor's primary objective was to steal credentials, specifical...

Read full article

Affected Software

1 affected component
Salesloft Drift
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a connection between Salesforce data thefts and a breach involving the Salesloft Drift app.

2

What security implications are discussed in the article?

The article highlights the risk of attackers stealing OAuth tokens, compromising Salesforce data.

3

What products or software are affected by this breach?

The affected software includes the Salesloft Drift app, which integrates with Salesforce.

4

How did the attackers gain access to Salesforce data?

Attackers gained access by stealing OAuth tokens from the Salesloft Drift app.

5

What function does the Salesloft Drift app serve in relation to Salesforce?

The Salesloft Drift app is used to automate sales processes and pulls relevant information from Salesforce databases.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203