Google Links Salesforce Data Thefts to Salesloft Breach
Attackers exploited Salesloft's OAuth tokens via the Drift integration to access Salesforce data, stealing credentials including AWS keys and Snowflake tokens, officials said.
10 Articles
10 Articles
Hundreds of Salesforce customers impacted by attack spree linked to third-party AI agent
Google Threat Intelligence Group warned about a “widespread data theft campaign” that compromised hundreds of Salesforce customers over a 10-day span earlier this month. According to a report published Tuesday, researchers say a threat group Google tracks as UNC6395 stole large volumes of data from Salesforce customer instances by using stolen OAuth tokens from Salesloft Drift, a third-party AI chat agent for sales and leads. Google said the at…


Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks
Hackers breached sales automation platform Salesloft to steal OAuth and refresh tokens from its Drift chat agent integration with Salesforce to pivot to customer environments and exfiltrate data. The ShinyHunters extortion group claims responsibility for these additional Salesforce attacks.
ShinyHunters Breach Salesloft Integration, Steal Customer Data
In the intricate world of enterprise software, where sales automation platforms like Salesloft promise seamless integrations to boost revenue workflows, a recent cyberattack has exposed the vulnerabilities lurking in third-party connections. Hackers infiltrated Salesloft’s systems, specifically targeting its Drift chat agent integration with Salesforce, to pilfer OAuth and refresh tokens. These digital keys allowed the attackers to pivot into cu…
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium