Concise Cybersecurity Intelligence for Decision-Makers
In August 2025, a sophisticated supply-chain attack against the marketing-automation tool SalesLoft Drift exploited its integration with Salesforce via stolen OAuth and refresh tokens. The threat actor — tracked by Google Threat Intelligence Group as UNC6395 — accessed hundreds of corporate environments between roughly August 8–18, exfiltrating large volumes of CRM data and hunting for embedded secrets such as AWS access keys, Snowflake tokens and plaintext passwords.
The incident showed us how a single compromised third-party integration can rapidly amplify across organisations, including major tech and cybersecurity firms.
In our CMA Cyber Insights document, we break down exactly what happened — the timeline, the root cause (which began with a GitHub account compromise at Salesloft between March and June 2025), the exploitation method, and the global blast radius. Crucially, we distil the key lessons for businesses of all sizes.
For a deeper dive into the SalesLoft Drift breach — including sector-specific impacts, actionable checklists, and best-practice frameworks to strengthen your incident-response and resilience programme — download our full Cyber Insights Document now.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.