IntelliOS Threat Intel Operating System
IntelliOSPANDAModule|AIFlash Threat Intel Brief

Salesloft Drift

Supply Chain Attack Against Salesforce

OAuth tokensSalesforceSaaS integration risk
Published
23-Jun-2026
Brief Version
v1.4
Updated
0x via AI Monitoring Agents
Next AI Monitor
Not scheduled - no AI Monitoring Agent assigned
Brief ID
PANDA-FTIB-SALESLOFT-DRIFT-2026-001
Template
Flash Threat Brief Template v2.0

Research Framing

Salesloft Drift Campaign Snapshot

1-Topic

This brief covers the Salesloft Drift OAuth supply-chain attack, where a trusted SaaS integration became the route into downstream Salesforce environments. The practical topic is not a Salesforce platform CVE; it is connected-app trust, OAuth material, API data access, CRM scoping, and victim-specific disclosure boundaries.1, 2, 3, 5, 8

FocusSource-Backed Answer
What happened?Public reporting says compromised Salesloft Drift OAuth tokens were used to access Salesforce data in downstream customer tenants.
Why supply chain?The access path flowed through a trusted third-party SaaS integration rather than a direct exploit against each customer tenant.
Defensive centerInventory Drift/Salesloft connected apps, revoke or rotate tokens, preserve Salesforce logs, scope object access, and rotate secrets found inside CRM data.

2-Persona / Audience Lens

3-BLUF

  • Salesloft Drift was a trusted SaaS integration path into downstream Salesforce environments; public reporting frames the incident around stolen OAuth tokens rather than a Salesforce core-platform exploit. 1, 2, 3, 5
  • Google Cloud attributes the activity to UNC6395 and describes widespread Salesforce data theft between August 8 and August 18, 2025; FINRA states the same cluster is also known as GRUB1, a name Cloudflare used in its first-party incident write-up. 1, 7, 17
  • The supply-chain issue is the integration trust bridge: an attacker who controls or steals OAuth/refresh tokens from a SaaS provider can query customer Salesforce data without first compromising each customer by phishing. 1, 3, 4, 8
  • Immediate response should prioritize Drift/Salesloft connected-app inventory, token revocation, reauthorization review, Salesforce API/event-log preservation, and secret hunting inside CRM data. 1, 3, 4, 7
  • The Klue incident is a later, highly relevant comparator: it shows the same Salesforce SaaS/OAuth supply-chain class recurring in 2026, but it is not evidence that Klue and Drift share one operator or infrastructure set. 14, 15, 16

4-Executive Summary

Salesloft Drift is a conversational marketing, chatbot, and revenue-workflow platform that can integrate with Salesforce. That integration is why the incident is a supply-chain event: downstream customers could be exposed through OAuth tokens associated with a trusted SaaS application, even if their own users were not phished first and Salesforce itself was not exploited as a platform vulnerability. 1, 2, 3, 8

Google Cloud/GTIG reports that UNC6395 used compromised Salesloft Drift OAuth tokens to conduct widespread Salesforce data theft between August 8 and August 18, 2025. FINRA identifies the same cluster as UNC6395, also known as GRUB1; Cloudflare likewise uses GRUB1 in its first-party impact statement. BleepingComputer, Arctic Wolf, Unit 42, FINRA, and FBI/IC3 reporting reinforce the same core pattern: trusted integration tokens, downstream Salesforce access, data theft, and extortion-adjacent risk. 1, 2, 3, 4, 5, 7, 17

The response is token-first and tenant-specific. Organizations should identify Drift/Salesloft connected apps, revoke or rotate OAuth/refresh tokens, preserve Salesforce Event Monitoring and API logs, scope accessed objects, and search CRM records for embedded credentials, secrets, or sensitive customer context that may require follow-on rotation or notification. 1, 3, 4, 7

Public victim disclosures make the impact more concrete. Cloudflare described access to Salesforce case data and emphasized customer-scoping boundaries; Zscaler, Palo Alto Networks, and Proofpoint each published narrower incident-response statements that help distinguish CRM data exposure from compromise of core products or services. These examples are useful because they show how the same OAuth supply-chain path can produce different notification, legal, and forensic questions depending on what the connected app could access in each tenant. 17, 18, 19, 20

The May 2026 Salesforce Help page should not be confused with the campaign window. It is a useful official reference for the Drift app unauthorized-access incident, but the central public campaign reporting and government advisory are August to September 2025. That date discipline matters because teams may otherwise mistake this for a newly disclosed May 2026 intrusion wave. 1, 5, 6

Expansion Research Add
Klue is the most relevant later comparator. In both stories, the center of gravity is not endpoint malware or a core Salesforce CVE; it is SaaS integration trust, OAuth material, connected apps, API access, and downstream customer scoping. 14, 15, 16

5-AI Agent Delta Updates

6-Why It Matters

7-Timeline

8-Incident Response Playbook Ideas

9-Term Glossary

10-TTPs

11-CVE / Vulnerability References

12-IOCs / Observables

13-Threat Actor Glossary

14-Common Questions Q&A

15-Talking Points

16-Decision Ready Actions

17-Exploitable Technology Risks

18-Social Media / Community Signals

19-Tier 0 Through Tier 8 Source Summary

20-About The Contributors

21-Source Deconfliction

22-Real World Examples

23-Public Victims / Disclosure Matrix

24-KEV and CVE Details

25-MITRE ATT&CK Lifecycle Mapping

26-Stats / Visual Snapshot

27-Additional IntelliOS Threat Intel Products on This Topic

28-Notes

29-Citations

30-Version Change Log