Skip to main content
See every side of every news story
Published loading...Updated

Salesloft: March GitHub Repo Breach Led to Salesforce Data Theft Attacks

Threat actor UNC6395 accessed Salesloft's GitHub and AWS environments from March to June, stealing OAuth tokens used to compromise hundreds of organizations in August, Mandiant found.

Summary by BleepingComputer
Salesloft says attackers first breached its GitHub account in March, leading to the theft of Drift OAuth tokens later used in widespread Salesforce data theft attacks in August. [...]

10 Articles

SecurityBrief New ZealandSecurityBrief New Zealand
+2 Reposted by 2 other sources

Salesloft breach exposed sensitive data of 700+ firms, including Cloudflare and Palo Alto Networks, after hackers exploited OAuth tokens via a prolonged GitHub intrusion.

A GitHub repository belonging to US marketing company Salesloft was hacked, exposing AWS environment credentials. Hackers used these credentials to obtain OAuth tokens, allowing them to access CRM data from companies like Cloudflare and Google. The incident affected at least 750 companies.

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality 

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

iTnews broke the news in on Monday, September 8, 2025.
Sources are mostly out of (0)
News
For You
Search
BlindspotLocal