2025-08-08 (incident) · US · Salesloft
Salesloft Drift OAuth tokens used to take Salesforce data, 2025
Disclosed by the affected organisation.
An attacker accessed Salesloft's GitHub account between March and June 2025, then reached Drift's AWS environment and took OAuth tokens for Drift customers' integrations. From 8 to 18 August 2025, the group Google tracks as UNC6395 used the tokens to export large volumes of data from many companies' Salesforce instances and searched it for secrets such as AWS keys and Snowflake tokens. No social engineering of staff was involved: the attacker used OAuth tokens taken from a supplier's integration, and Google said no Salesforce vulnerability was involved. The FBI grouped UNC6395 with actors behind data theft and extortion.
Timeline
- 2025-03-22 The intrusion timeline found by Mandiant begins, with access to Salesloft's GitHub account and reconnaissance.
- 2025-08-08 UNC6395 begins using stolen Drift OAuth tokens to export data from Salesforce instances, continuing until at least 18 August.
- 2025-08-20 Salesloft, with Salesforce, revokes all active access and refresh tokens for the Drift application.
- 2025-08-26 Google Threat Intelligence publishes its analysis, and Salesloft engages Mandiant.
- 2025-09-12 The FBI issues a FLASH alert on UNC6040 and UNC6395 targeting Salesforce platforms.
- 2025-09-30 Mandiant's investigation and remediation conclude.
Lessons
- Inventory the third-party apps connected to your SaaS platforms and revoke tokens you no longer need.
- Do not store passwords, access keys or tokens in CRM records or support cases, where a data export exposes them.
- Restrict connected app access by IP range and alert on large exports through integrations.
Scam types: Data theft extortion
Sources
- Salesloft Trust Center: Update on Mandiant Drift and Salesloft application investigations (Company disclosure, primary, accessed 2026-09-24)
- FBI FLASH-20250912-001: Cyber criminal groups UNC6040 and UNC6395 compromising Salesforce instances for data theft and extortion (Law enforcement, primary, accessed 2026-09-24)
- Google Threat Intelligence: Widespread data theft targets Salesforce instances via Salesloft Drift (Vendor research, secondary, accessed 2026-09-24)