Cyber Insights: SalesLoft Drift

Concise Cybersecurity Intelligence for Decision-Makers

SalesLoft Drift Image Final (1)

Download Our Cyber Insights Document on the SalesLoft Drift Cyber Attack

In August 2025, a sophisticated supply-chain attack against the marketing-automation tool SalesLoft Drift exploited its integration with Salesforce via stolen OAuth and refresh tokens. The threat actor — tracked by Google Threat Intelligence Group as UNC6395 — accessed hundreds of corporate environments between roughly August 8–18, exfiltrating large volumes of CRM data and hunting for embedded secrets such as AWS access keys, Snowflake tokens and plaintext passwords. 

The incident showed us how a single compromised third-party integration can rapidly amplify across organisations, including major tech and cybersecurity firms. 

In our CMA Cyber Insights document, we break down exactly what happened — the timeline, the root cause (which began with a GitHub account compromise at Salesloft between March and June 2025), the exploitation method, and the global blast radius. Crucially, we distil the key lessons for businesses of all sizes.

For a deeper dive into the SalesLoft Drift breach — including sector-specific impacts, actionable checklists, and best-practice frameworks to strengthen your incident-response and resilience programme — download our full Cyber Insights Document now. 

Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.

  • ** GDPR ** We wholeheartedly believe your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data. 
  • Align with the GDPR requirements.
  • Increase your Breach Readiness.
  • Reduce your time to detect and respond.

Complete the form below to receive a copy of CMA Cyber Insights on the SalesLoft Drift Cyber Attack

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

FAQs about the SalesLoft Drift Attack

  • 1. What happened in the Salesloft Drift cyber attack?
    The Salesloft Drift cyber attack was a supply-chain compromise in which attackers obtained OAuth credentials associated with Drift’s third-party integrations. These credentials were subsequently used to access and exfiltrate data from connected customer environments, including numerous Salesforce instances. 
  • 2. When did the Salesloft Drift cyber attack take place?
    The main data-exfiltration campaign occurred between approximately 8 and 18 August 2025. However, the wider intrusion reportedly began earlier, when the threat actor accessed Salesloft’s GitHub environment and conducted reconnaissance between March and June 2025. 
  • 3. How did the attackers compromise Salesloft Drift?
    The investigation found that the attackers initially gained access to Salesloft’s GitHub account. They later accessed Drift’s AWS environment and obtained OAuth tokens belonging to customer integrations. These stolen tokens enabled them to access connected systems without needing users’ passwords. 
  • 4. Who was responsible for the Salesloft Drift cyber attack?
    Google Threat Intelligence Group tracks the threat actor responsible for the campaign as UNC6395. This is a temporary designation used to identify and monitor the group’s malicious activity; it does not necessarily confirm the attackers’ real-world identity or organisational affiliation. 
  • 5. What information was targeted in the Salesloft Drift breach?
    The attackers exported substantial volumes of CRM data, including information stored in Salesforce Accounts, Cases, Users and Opportunities. They also searched the stolen data for credentials and secrets such as AWS access keys, Snowflake tokens, API credentials and plaintext passwords. 
  • 6. Was the Salesforce platform itself compromised?
    The incident was not attributed to a vulnerability in Salesforce’s core platform. Attackers accessed individual customer environments by abusing OAuth tokens associated with the compromised Drift integration, demonstrating how a trusted third-party connection can become an indirect route into business-critical systems. 
  • 7. What should organisations do following the Salesloft Drift incident?
    Potentially affected organisations should review every application connected to their Drift environment, revoke and rotate OAuth tokens, API keys, passwords and other exposed credentials, and examine authentication and event logs for suspicious activity. Connected applications should also be restricted according to least-privilege principles. 
  • 8. What does the CMA Cyber Insights document cover?
    The CMA Cyber Insights document examines the attack timeline, initial compromise, exploitation of OAuth tokens and the wider impact on connected organisations. It also provides actionable recommendations, sector-specific considerations and best-practice measures for improving third-party risk management, incident response and operational resilience. 

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • The form above collects personal information so we may email you the requested information and pressing the "Get your free copy now"  button acts as informed consent for this processing purpose. Consequently we may be in touch to:

    • Update you when we host our ground-breaking Wisdom of Crowds events in your country or region.
    • Keep you posted on free resources and documents around Wisdom of Crowds events and its outputs. (For example, we tend to create insightful mind maps and we also are the creators of free to view Insights with Cyber Leaders Video Interviews. )
    • Ping you a note about upcoming FREE educational webinars on GDPR and Cybersecurity.
    • Inform you of any upcoming Data Breach Response or Cyber Incident Response training.  
  • Using the information from this page we will NOT sell or market to you any of our consultancy or trusted advisory services.  
  • In its purest interpretation, this act of us communicating with you is direct marketing and is processed on the basis of our legitimate interest and your engaging in our services. All marketing communication will include an unsubscribe button or other method of ending communication.