SolarWinds has issued an announcement regarding the recent security incident involving the Salesloft Drift integration for Salesforce that led to unauthorized access to data.

The company confirmed that its own systems were not affected by the breach, but it is taking the issue very seriously.
The incident began with compromised OAuth tokens associated with the Salesloft Drift app, a popular tool used to integrate sales and marketing functions with Salesforce. Attackers exploited these compromised tokens to gain unauthorized access to multiple Salesforce customer environments.
Once inside, they were able to extract significant amounts of data. The threat actors' main goal appears to have been to obtain sensitive credentials, such as access keys and passwords, that were stored on the compromised Salesforce instances.
See also: CISA: Two malware exploits Ivanti EPMM vulnerabilities
This type of attack highlights the dangers of third-party service, where a vulnerability in one application can create an outlet in a much larger ecosystem, affecting multiple organizations that rely on the same software stack.

SolarWinds: Not affected by Salesloft – Salesforce hack
SolarWinds launched an internal investigation to assess the potential for risk. The company’s security team found that while SolarWinds uses Salesforce as part of its business operations, it does not use the Salesloft Drift integration. As a result, the Salesforce instance was not vulnerable to the specific attack used in this breach.
In a public statement, the company confirmed that its systems and data remain secure. Although it was not directly impacted, SolarWinds stressed that it is treating the incident as a high priority issue and has proactively reviewed its internal security protocols to ensure the integrity of its environment.
See also: Critical vulnerability in Microsoft Entra ID allows full administrative control
The company is also constantly monitoring the situation for any evolving threats. This event serves as a critical reminder of the supply chain risks inherent in modern cloud-based software environments. Many organizations rely on a network of interconnected third-party applications to enhance the functionality of core platforms like Salesforce. However, each integration adds a new layer to the organization’s attack surface.
The breach of OAuth tokens, in particular, poses a powerful threat, as these tokens can grant applications extensive permissions to access, modify, and extract data. The incident surrounding the Salesforce integration of Salesloft Drift serves as a wake-up call for the broader cloud industry. In a world where businesses “build” their daily operations on a web of third-party APIs and applications, the OAuth token breach shows how easily a chain of events can be set in motion. It’s not just about data theft; it’s about how a single vulnerability can become a point of instability for the entire ecosystem.

The incident reminds organizations to conduct rigorous security auditing of all third-party applications and to regularly review the permissions granted to these integrations. Enforcing the principle of least privilege and implementing strong monitoring for unusual data access patterns are essential measures to mitigate such risks.
See also: CountLoader: Russian hackers use new malware loader
SolarWinds was not targeted, but its response—preemptively hardening internal protocols—points in the right direction: no organization can afford to think of itself as “out of danger.” Monitoring integrations, strict credential management, and adopting a zero trust architecture should become the norm. As attacks become more targeted, true resilience will depend on how seriously organizations take the risk their own partnerships pose.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
