Skip to main content
See every side of every news story
Published loading...Updated

Palo Alto Investigates Data Theft After Hackers Exploit Stolen OAuth Tokens - Palo Alto Networks (NASDAQ:PANW)

Threat actor UNC6395 exploited stolen OAuth tokens from Salesloft Drift to access Salesforce data across hundreds of organizations, exposing sensitive credentials and customer information.

  • Between Aug. 8 and Aug. 18, Salesloft's Drift application suffered an intrusion affecting OAuth credentials, and Palo Alto Networks and Zscaler confirmed they were among hundreds impacted via Salesforce.
  • Google Threat Intelligence traced the activity to UNC6395, which used compromised OAuth tokens tied to Salesloft Drift to harvest AWS access keys and Snowflake-related access tokens from Salesforce data on Tuesday.
  • Cloudflare said its review found 104 Cloudflare API tokens and that exfiltrated data mainly included Salesforce case objects with support-ticket text and configuration details, not attachments.
  • Companies disabled the Drift integration, revoked OAuth tokens, and notified exposed customers directly, while Cloudflare urged credential rotations, saying it's "strongly urge you to rotate any credentials that you may have shared with us through this channel."
  • Cyble reported supply-chain attacks have doubled in recent months, and last week TransUnion disclosed a Salesforce-related incident exposing data of 4.4 million customers.
Insights by Ground AI
Does this summary seem wrong?

16 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality 

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

The Register broke the news in on Tuesday, September 2, 2025.
Sources are mostly out of (0)
News
For You
Search
BlindspotLocal