A sophisticated supply chain attack that affected over 700 organizations, including major cybersecurity firms, has been traced back to a breach of Salesloft Drift's GitHub account, which began as early as March 2025. In an update on September 6, 2025, Salesloft confirmed that an investigation by cybersecurity firm Mandiant found that attackers exploited this initial access to ultimately steal OAuth tokens from the Salesloft Drift chat platform, leading to extensive data theft from customer systems.
See also: PagerDuty confirms breach after Salesforce leak

The investigation, which began on August 28, revealed that the attackers had access to Salesloft’s GitHub account from March to June 2025. During this time, the attackers downloaded content from private repositories, added a guest user, and created workflows while conducting reconnaissance on both Salesloft and Drift’s application environments. While the Salesloft platform itself was not compromised, the attackers moved to Drift’s AWS environment, where they were able to obtain OAuth tokens for customer technology integrations.
The attacker, identified by Google’s Threat Intelligence Team as UNC6395, used these stolen tokens between August 8 and 18 to access and extract data from customers’ built-in applications, primarily Salesforce cases. The stolen data primarily included business contact information, such as names, email addresses, and job titles, as well as content from support cases.
See also: Salesloft temporarily withdraws Drift after OAuth Tokens were stolen

The breach affected a wide range of high-profile companies, including Cloudflare, Zscaler, Palo Alto Networks, PagerDuty and SpyCloud. The incident is considered one of the largest recent attacks on the SaaS supply chain, highlighting the risks associated with third-party application integrations. In response to the attack, Salesloft partnered with Mandiant and took decisive action to mitigate the threat. The company fully decommissioned the Drift platform, isolated its infrastructure and refreshed all affected credentials.
Mandiant has since verified that the incident has been contained and that the technical separation between the Salesloft and Drift environments prevented the attackers from moving laterally. The focus of the investigation has now shifted to a quality assurance review. Salesloft has issued guidance to its partners, suggesting that they proactively revoke the existing API key for all third-party applications integrated with Drift.
See also: Zscaler confirms data breach after Salesloft Drift attack

The company also published a list of Indicators of Compromise (IOCs), including malicious IP addresses and user-agent strings, to help customers look for suspicious activity in their own logs. While a group called “Scattered LAPSUS$ Hunters 4.0” claimed responsibility, researchers have not found credible evidence to support this claim.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
