HomeSecuritySalesloft temporarily withdraws Drift after OAuth Tokens were stolen

Salesloft temporarily withdraws Drift after OAuth Tokens were stolen

Salesloft announced Tuesday that it is temporarily retiring Drift, as multiple companies have been implicated in a widespread supply chain attack that targeted the marketing software, resulting in the mass theft of authentication tokens.

 Salesloft Drift

“ This will provide the fastest path to fully examine the application and enhance resiliency and security in the system. The application will then be fully operational again ,” the company said . “ As a result, the Drift chatbot on customer sites will be unavailable and Drift will not be accessible .”

The company said its top priority is ensuring the integrity and security of its systems data and customer . It also said it is working with cybersecurity firms Mandiant and Coalition as part of its efforts to address the incident.

See also: Cloudflare: Customer data breach (via Salesloft)

This development comes after the Google Threat Intelligence Group (GTIG) and Mandiant an extensive data theft campaign that leveraged stolen OAuth and refresh tokens (associated with the AI ​​chat agent Drift) to compromise customers' Salesforce environments.

“Beginning on August 8, 2025, until at least August 18, 2025, the perpetrator targeted Salesforce customer environments via compromised OAuth tokens associated with the third-party Salesloft Drift application,” the company said last week.

The activity has been attributed to a threat group codenamed UNC6395 (also known as GRUB1), with Google telling The Hacker News that more than 700 organizations may have been affected.

Salesloft temporarily withdraws Drift after OAuth Tokens were stolen

While it was initially claimed that the breach was limited to Salesloft's integration with Salesforce, it has since emerged that any platform integrated with Drift is potentially compromised. The exact way the perpetrators initially gained access to Salesloft Drift remains unknown.

See also: Jaguar Land Rover suffered a cyberattack

The incident has led Salesforce to temporarily disable all Salesloft integrationsas a precautionary measure. Some of the businesses that have confirmed being affected by the breach include:

“We believe this was not an isolated incident but that the attacker intended to harvest customer credentials and information for future attacks,” Cloudflare said. “Given that hundreds of organizations were impacted through this Drift breach, we suspect the attacker will use this information to launch targeted attacks against customers across all affected organizations.”

The Salesloft incident should mobilize all organizations

Salesloft’s decision to temporarily remove Drift shows how vulnerable businesses can become when they rely on complex third-party software ecosystems. The issue is not just technical, but also strategic: a chatbot that is considered a marketing tool can turn into an Achilles heel for global infrastructure. The case highlights the growing importance of supply chain security, as the attack was not limited to one organization, but affected hundreds.

See also: Silver Fox leverages Microsoft WatchDog to develop ValleyRAT

Salesloft temporarily withdraws Drift after OAuth Tokens were stolen

Notably, the attackers did not stop at immediate access to data, but instead aimed to obtain credentials and tokens that pave the way for future attacks. This means that the consequences may not yet have peaked – affected companies should prepare for a prolonged period of heightened risk.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Working with specialist companies like Mandiant shows seriousness in the response, but the fact that the initial access highlights the magnitude of the uncertainty. The Drift crisis is a stark reminder: any SaaS integration can become the weakest link, and trust in cloud platforms must be accompanied by ongoing monitoring and rigorous risk management.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS