HomeSecuritySalesloft Drift attack linked to GitHub breach

Salesloft Drift attack linked to GitHub breach

A sophisticated supply chain attack that affected over 700 organizations, including major cybersecurity firms, has been traced back to a breach of Salesloft Drift's GitHub account, which began as early as March 2025. In an update on September 6, 2025, Salesloft confirmed that an investigation by cybersecurity firm Mandiant found that attackers exploited this initial access to ultimately steal OAuth tokens from the Salesloft Drift chat platform, leading to extensive data theft from customer systems.

See also: PagerDuty confirms breach after Salesforce leak

Salesloft Drift

The investigation, which began on August 28, revealed that the attackers had access to Salesloft’s GitHub account from March to June 2025. During this time, the attackers downloaded content from private repositories, added a guest user, and created workflows while conducting reconnaissance on both Salesloft and Drift’s application environments. While the Salesloft platform itself was not compromised, the attackers moved to Drift’s AWS environment, where they were able to obtain OAuth tokens for customer technology integrations.

The attacker, identified by Google’s Threat Intelligence Team as UNC6395, used these stolen tokens between August 8 and 18 to access and extract data from customers’ built-in applications, primarily Salesforce cases. The stolen data primarily included business contact information, such as names, email addresses, and job titles, as well as content from support cases.

See also: Salesloft temporarily withdraws Drift after OAuth Tokens were stolen

Salesloft Drift attack linked to GitHub breach
Salesloft Drift attack linked to GitHub breach

The breach affected a wide range of high-profile companies, including Cloudflare, Zscaler, Palo Alto Networks, PagerDuty and SpyCloud. The incident is considered one of the largest recent attacks on the SaaS supply chain, highlighting the risks associated with third-party application integrations. In response to the attack, Salesloft partnered with Mandiant and took decisive action to mitigate the threat. The company fully decommissioned the Drift platform, isolated its infrastructure and refreshed all affected credentials.

Mandiant has since verified that the incident has been contained and that the technical separation between the Salesloft and Drift environments prevented the attackers from moving laterally. The focus of the investigation has now shifted to a quality assurance review. Salesloft has issued guidance to its partners, suggesting that they proactively revoke the existing API key for all third-party applications integrated with Drift.

See also: Zscaler confirms data breach after Salesloft Drift attack

Salesloft Drift attack linked to GitHub breach
Salesloft Drift attack linked to GitHub breach

The company also published a list of Indicators of Compromise (IOCs), including malicious IP addresses and user-agent strings, to help customers look for suspicious activity in their own logs. While a group called “Scattered LAPSUS$ Hunters 4.0” claimed responsibility, researchers have not found credible evidence to support this claim.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS