Skip to content

2025-08-08 (incident) · US · Salesloft

Salesloft Drift OAuth tokens used to take Salesforce data, 2025

Disclosed by the affected organisation.

An attacker accessed Salesloft's GitHub account between March and June 2025, then reached Drift's AWS environment and took OAuth tokens for Drift customers' integrations. From 8 to 18 August 2025, the group Google tracks as UNC6395 used the tokens to export large volumes of data from many companies' Salesforce instances and searched it for secrets such as AWS keys and Snowflake tokens. No social engineering of staff was involved: the attacker used OAuth tokens taken from a supplier's integration, and Google said no Salesforce vulnerability was involved. The FBI grouped UNC6395 with actors behind data theft and extortion.

Timeline

  1. 2025-03-22 The intrusion timeline found by Mandiant begins, with access to Salesloft's GitHub account and reconnaissance.
  2. 2025-08-08 UNC6395 begins using stolen Drift OAuth tokens to export data from Salesforce instances, continuing until at least 18 August.
  3. 2025-08-20 Salesloft, with Salesforce, revokes all active access and refresh tokens for the Drift application.
  4. 2025-08-26 Google Threat Intelligence publishes its analysis, and Salesloft engages Mandiant.
  5. 2025-09-12 The FBI issues a FLASH alert on UNC6040 and UNC6395 targeting Salesforce platforms.
  6. 2025-09-30 Mandiant's investigation and remediation conclude.

Lessons

Scam types: Data theft extortion

Sources

  1. Salesloft Trust Center: Update on Mandiant Drift and Salesloft application investigations (Company disclosure, primary, accessed 2026-09-24)
  2. FBI FLASH-20250912-001: Cyber criminal groups UNC6040 and UNC6395 compromising Salesforce instances for data theft and extortion (Law enforcement, primary, accessed 2026-09-24)
  3. Google Threat Intelligence: Widespread data theft targets Salesforce instances via Salesloft Drift (Vendor research, secondary, accessed 2026-09-24)