Skip to main content
See every side of every news story
Published loading...Updated

Google Warns that Mass Data Theft Hitting Salesloft AI Agent Has Grown Bigger

Threat actor UNC6395 exploited OAuth tokens from Salesloft Drift to exfiltrate data from over 700 Salesforce instances and some Google Workspace accounts, prompting token revocations and security advisories.

  • On August 29, 2025, Google disclosed that a cyberattack on Salesloft's Drift AI agent compromised OAuth tokens across multiple integrations, including Salesforce and Google Workspace.
  • The attack began around August 8 and lasted about ten days, with threat actor UNC6395 stealing tokens through Salesloft Drift and accessing Salesforce data and some Google Workspace emails.
  • Salesloft confirmed the breach on August 25, revoked all Drift-linked OAuth tokens by August 20, pulled Drift from AppExchange, and advised customers to treat all related tokens as compromised.
  • Austin Larsen of GTIG said over 700 organizations might be impacted, while Cory Michal and Pingree highlighted the attack's operational discipline and automation enabling large-scale data exfiltration.
  • Google disabled the Drift integration, revoked tokens, notified affected users, urged credential rotation and audits, and warned that stolen credentials could fuel future supply-chain or ransomware attacks.
Insights by Ground AI
Does this summary seem wrong?

15 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality 

To view factuality data please Upgrade to Premium

Ownership

To view ownership data please Upgrade to Vantage

SecurityBrief Australia broke the news in on Thursday, August 28, 2025.
Sources are mostly out of (0)
News
For You
Search
BlindspotLocal