A malicious actor (UNC6395) managed to obtain Salesforce OAuth tokens from a third-party integration, called Salesloft Drift, and used these tokens to download large amounts of data from vulnerable Salesforce instances.

One of the attacker's goals was to find and extract additional credentials stored in Salesforce files to expand his access.
“ After extracting the data, the malicious actor searched the data for secrets that could be used to compromise the victims’ environments ,” the Google Threat Intelligence Group (GTIG) said . “ GTIG observed that UNC6395 targeted sensitive credentials such as Amazon Web Services (AWS) access keys (AKIA), passwords, and access tokens associated with Snowflake .”
See also: MixShell malware distributed via Contact Forms
Salesloft, a company that operates a “sales engagement and revenue orchestration” platform, has already identified and notified affected customers who connected their Salesforce systems to the Salesloft Drift AI live chat tool. While these users have already revoked their Salesforce authentication tokens, they should immediately begin internal investigations to determine what other credentials stored on Salesforce instances may have been compromised. They should also check to see if other external assets were accessed.
SaaS-to-SaaS integrations also create risks
OAuth provides an easy way for applications to authenticate with each other, and many platforms leverage this mechanism to integrate with other services . However, such integrations actually expand the attack surface.
Salesforce data theft
Salesloft detected the unauthorized activity on the Drift platform on August 20, but the abuse of OAuth tokens to access Salesforce data occurred between August 8 and 18. Google’s incident response team, Mandiant, noted that the malicious actor, which it tracks as UNC6395, extracted large amounts of data from “multiple enterprise Salesforce instances.”
See also: PoC Exploit released for Chrome zero-day vulnerability

Salesforce noted that the unauthorized access was not caused by a vulnerability in its own platform and has removed Salesloft Drift from the AppExchange pending further investigation. The affected access tokens have also been revoked.
The attackers executed SOQL queries to retrieve information related to Salesforce objects, such as Cases, Accounts, Users, and Opportunities, and extract data from them. Later, they deleted the query jobs. However, the logs were not affected, so organizations can review their logs to determine which queries were executed and what data the attackers stole.
What Salesloft Drift users should do
GTIG's report and Salesloft's advisory include breach indicators such as IP addresses used by the attackers and User-Agent strings for the tools they used to access the data.
Mandiant advises companies to also search the logs for any activity from known Tor (in addition to the IP addresses listed in the breach indicators) and open a support ticket with Salesforce to obtain a full list of queries executed by the attackers.
Organizations should search their Salesforce objects for any stored credentials and rotate them, especially those containing the terms AKIA (AWS), Snowflake, password, secret, and key.
Strings associated with organization login URLs , including VPN and SSO pages, should also be searched . An open source tool called TruffleHog can also be used to search for data for hardcoded secrets and credentials .
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Farmers Insurance: Data breach affects 1.1 million customers

“ We regularly see OAuth2 tokens and SaaS-to-SaaS integrations being compromised and abused ,” AppOmni’s Cory Michal told CSO . “ They have long been a known blind spot in most enterprise security programs. What surprised me was the sheer scale and methodical discipline that the attackers demonstrated. It wasn’t opportunistic, it seemed highly coordinated, with a level of planning and execution that suggests a state-sponsored adversary pursuing a broader mission .”
BleepingComputer reports that a spokesperson for the ransomware group ShinyHunters claimed to be behind the attack. ShinyHunters has been operating for several years and is responsible for alleged breaches at AT&T, Ticketmaster, and other organizations. The group has targeted Snowflake and AWS accounts in the past, as well as Salesforce in a recent vishing campaign that involved fake IT support calls.
