Salesloft Drift
Supply Chain Attack Against Salesforce
Research Framing
| Field | Value | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| User Topic | Salesloft Drift OAuth supply-chain attack involving Salesforce data theft, UNC6395, and downstream SaaS integration exposure. | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Interpreted Questions | What is Salesloft Drift? Why is this a supply-chain attack? How did stolen OAuth tokens affect Salesforce tenants? How should organizations identify and respond to exposure? | |||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Source Coverage |
|
Salesloft Drift Campaign Snapshot
Compromised Drift/Salesloft OAuth tokens enabled downstream Salesforce access.
GTIG reports widespread data theft between August 8 and August 18, 2025.
Primary GTIG/FBI label; FINRA and Cloudflare also reference GRUB1.
No scheduled PANDA AI Monitoring Agent is assigned to this page yet.
1-Topic
This brief covers the Salesloft Drift OAuth supply-chain attack, where a trusted SaaS integration became the route into downstream Salesforce environments. The practical topic is not a Salesforce platform CVE; it is connected-app trust, OAuth material, API data access, CRM scoping, and victim-specific disclosure boundaries.1, 2, 3, 5, 8
| Focus | Source-Backed Answer |
|---|---|
| What happened? | Public reporting says compromised Salesloft Drift OAuth tokens were used to access Salesforce data in downstream customer tenants. |
| Why supply chain? | The access path flowed through a trusted third-party SaaS integration rather than a direct exploit against each customer tenant. |
| Defensive center | Inventory Drift/Salesloft connected apps, revoke or rotate tokens, preserve Salesforce logs, scope object access, and rotate secrets found inside CRM data. |
2-Persona / Audience Lens
This brief is written for CISOs, Salesforce administrators, SaaS owners, SOC/IR teams, threat-intelligence analysts, legal/privacy teams, claims teams, and client-facing cyber advisors. It prioritizes what can be validated: Drift/Salesloft connected apps, OAuth token state, Salesforce API logs, CRM object exposure, secret rotation, and source-backed boundaries around attribution and timing.
3-BLUF
- Salesloft Drift was a trusted SaaS integration path into downstream Salesforce environments; public reporting frames the incident around stolen OAuth tokens rather than a Salesforce core-platform exploit. 1, 2, 3, 5
- Google Cloud attributes the activity to UNC6395 and describes widespread Salesforce data theft between August 8 and August 18, 2025; FINRA states the same cluster is also known as GRUB1, a name Cloudflare used in its first-party incident write-up. 1, 7, 17
- The supply-chain issue is the integration trust bridge: an attacker who controls or steals OAuth/refresh tokens from a SaaS provider can query customer Salesforce data without first compromising each customer by phishing. 1, 3, 4, 8
- Immediate response should prioritize Drift/Salesloft connected-app inventory, token revocation, reauthorization review, Salesforce API/event-log preservation, and secret hunting inside CRM data. 1, 3, 4, 7
- The Klue incident is a later, highly relevant comparator: it shows the same Salesforce SaaS/OAuth supply-chain class recurring in 2026, but it is not evidence that Klue and Drift share one operator or infrastructure set. 14, 15, 16
4-Executive Summary
Salesloft Drift is a conversational marketing, chatbot, and revenue-workflow platform that can integrate with Salesforce. That integration is why the incident is a supply-chain event: downstream customers could be exposed through OAuth tokens associated with a trusted SaaS application, even if their own users were not phished first and Salesforce itself was not exploited as a platform vulnerability. 1, 2, 3, 8
Google Cloud/GTIG reports that UNC6395 used compromised Salesloft Drift OAuth tokens to conduct widespread Salesforce data theft between August 8 and August 18, 2025. FINRA identifies the same cluster as UNC6395, also known as GRUB1; Cloudflare likewise uses GRUB1 in its first-party impact statement. BleepingComputer, Arctic Wolf, Unit 42, FINRA, and FBI/IC3 reporting reinforce the same core pattern: trusted integration tokens, downstream Salesforce access, data theft, and extortion-adjacent risk. 1, 2, 3, 4, 5, 7, 17
The response is token-first and tenant-specific. Organizations should identify Drift/Salesloft connected apps, revoke or rotate OAuth/refresh tokens, preserve Salesforce Event Monitoring and API logs, scope accessed objects, and search CRM records for embedded credentials, secrets, or sensitive customer context that may require follow-on rotation or notification. 1, 3, 4, 7
Public victim disclosures make the impact more concrete. Cloudflare described access to Salesforce case data and emphasized customer-scoping boundaries; Zscaler, Palo Alto Networks, and Proofpoint each published narrower incident-response statements that help distinguish CRM data exposure from compromise of core products or services. These examples are useful because they show how the same OAuth supply-chain path can produce different notification, legal, and forensic questions depending on what the connected app could access in each tenant. 17, 18, 19, 20
The May 2026 Salesforce Help page should not be confused with the campaign window. It is a useful official reference for the Drift app unauthorized-access incident, but the central public campaign reporting and government advisory are August to September 2025. That date discipline matters because teams may otherwise mistake this for a newly disclosed May 2026 intrusion wave. 1, 5, 6
5-AI Agent Delta Updates
| Field | Value |
|---|---|
| Initial publish date | June 23, 2026 |
| AI monitoring agent | Not yet scheduled for this brief. |
| Current delta status | Updated to the shared PANDA reader standard with FortiBleed-style header, card drawer, alert/share wiring, and compact card typography. |
6-Why It Matters
Salesforce integrations are often treated like routine business plumbing. Drift showed why they should be treated as privileged identity paths. When a trusted SaaS vendor holds OAuth access into customer CRM environments, compromise at the vendor layer can create a large downstream blast radius without requiring a new Salesforce CVE.
CRM concentration
Salesforce often contains customer contacts, opportunities, sales notes, cases, and business relationship context.
Token persistence
OAuth and refresh tokens can preserve access until revoked, rotated, or reauthorized under stricter controls.
Supply-chain recurrence
Klue later showed the same class of Salesforce SaaS/OAuth exposure recurring in 2026.
7-Timeline
| Date / Period | Event | Source-Backed Meaning | Source |
|---|---|---|---|
| August 8-18, 2025 | GTIG says UNC6395 conducted widespread Salesforce data theft using compromised Salesloft Drift OAuth tokens. | Core campaign window for the Drift incident. | 1 |
| August 26, 2025 | Google Cloud and BleepingComputer publish public reporting on the Salesloft Drift OAuth-token theft path. | Public technical and news baseline for the campaign. | 1, 2 |
| August 27, 2025 | Arctic Wolf publishes practitioner analysis and response framing. | Confirms no Salesforce platform compromise boundary and token response priorities. | 3 |
| September 2, 2025 | Unit 42 publishes hunting and mass-exfiltration threat brief. | Adds affected-object, secret-hunting, and query-job deletion context. | 4 |
| September 12, 2025 | FBI/IC3 publishes advisory on UNC6040 and UNC6395 compromising Salesforce platforms. | Government-level corroboration and actor/TTP context. | 5 |
| September 2025 | Cloudflare, Zscaler, Palo Alto Networks, and Proofpoint publish first-party impact statements or incident-response summaries. | Named examples show the practical downstream CRM-data scoping problem. | 17, 18, 19, 20 |
| May 4, 2026 | Salesforce Help page for Drift App unauthorized-access incident is published/updated. | Useful official reference date; not the original campaign start date. | 6 |
| June 23, 2026 | PANDA adds the Klue comparator as expansion research. | Shows recurrence of Salesforce SaaS/OAuth supply-chain risk. | 14, 15, 16 |
8-Incident Response Playbook Ideas
| Phase | Playbook Idea | Likely Owner | Sources |
|---|---|---|---|
| Identify exposure | Find Salesloft Drift connected apps, OAuth grants, refresh-token use, and integration users across Salesforce tenants. | Salesforce Admin / IAM | 1, 3, 8 |
| Contain | Revoke Drift/Salesloft OAuth tokens, force reauthentication, rotate secrets stored in or accessible through Salesforce, and reauthorize only if required. | IAM / Salesforce Admin | 1, 3, 4 |
| Preserve | Retain Salesforce Event Monitoring, LoginHistory, Setup Audit Trail, connected-app OAuth usage, API query logs, and any vendor notices. | SOC / IR | 3, 4 |
| Scope data | Review Account, Contact, Lead, Opportunity, Case, Task/Event, and custom-object access; search for credentials or secrets stored in CRM fields. | IR / Legal / Business Owner | 1, 4, 7 |
| Notify / govern | Coordinate legal, privacy, and vendor-risk decisions based on confirmed data access and business relationship exposure. | Counsel / Privacy / Vendor Risk | 5, 7 |
9-Term Glossary
| Term | Meaning Here | Sources |
|---|---|---|
| Salesloft Drift | A Salesloft application used for conversational marketing, chatbot, and revenue-workflow integration with platforms such as Salesforce. | 1, 6 |
| OAuth token | An authorization artifact that lets an application access resources without repeatedly using the user password. | 1, 8 |
| Connected app | A Salesforce application trust relationship that can authorize API access through OAuth-style flows. | 8 |
| UNC6395 | The threat cluster Google Cloud/GTIG associated with the Salesloft Drift OAuth-token activity. | 1 |
| GRUB1 | A naming label FINRA lists as another name for UNC6395; Cloudflare uses GRUB1 in its incident write-up for the actor observed in its Salesforce tenant. | 7, 17 |
| UNC6040 | A separate Salesforce-focused threat cluster discussed in the FBI/IC3 advisory, primarily relevant here as a boundary so Drift/UNC6395 activity is not conflated with voice-phishing/social-engineering intrusions. | 5 |
| ShinyHunters | An extortion label referenced by FBI/IC3 in the broader Salesforce compromise context; this brief does not use it as the primary name for the Salesloft Drift campaign. | 5 |
10-TTPs
| TTP | MITRE ATT&CK ID | Source-Backed Detail | Sources |
|---|---|---|---|
| Trusted SaaS integration abuse | T1199: Trusted Relationship | Drift/Salesloft OAuth trust became the route into downstream Salesforce environments. | 1, 5, 9 |
| OAuth token theft / reuse | T1528: Steal Application Access Token | Stolen OAuth/refresh tokens were central to the reported Salesforce data access. | 1, 2, 10 |
| Valid-token access | T1078: Valid Accounts | Activity can appear as authorized connected-app/API access unless logs are reviewed. | 3, 4, 11 |
| Automated Salesforce collection | T1119: Automated Collection | Unit 42 describes mass query and collection patterns against Salesforce objects. | 4, 12 |
| Cloud/API data exfiltration | T1567: Exfiltration Over Web Service | Map exact exfiltration behavior to tenant telemetry before labeling final impact. | 1, 4, 13 |
11-CVE / Vulnerability References
12-IOCs / Observables
| Observable Type | Indicator / Lead | What To Hunt / Collect | Sources |
|---|---|---|---|
| Connected app | Salesloft Drift app authorization, OAuth grants, refresh tokens, and integration-user activity. | Connected app inventory, OAuth usage events, authorized users, app scopes, last-used timestamps. | 1, 3, 8 |
| API behavior | High-volume REST API queries, object enumeration, and unusual Query/QueryMore activity. | Salesforce Event Monitoring API logs, query history, source IPs, user agents, object names. | 1, 4 |
| Secret exposure | Credentials, API keys, tokens, or customer secrets stored in Salesforce fields, cases, notes, or custom objects. | Targeted searches across sensitive CRM objects and follow-on secret rotation evidence. | 1, 4, 7 |
| Anti-forensics | Query-job deletion or attempts to remove evidence of Salesforce query activity. | Setup Audit Trail, API event logs, and administrative activity around job/query objects. | 4 |
| Boundary | No single universal IOC list proves exposure for every tenant. | Use vendor notices and local Salesforce telemetry for deterministic scoping. | 3, 6 |
13-Threat Actor Glossary
Use UNC6395 as the primary name for the Salesloft Drift OAuth-token campaign because that is the GTIG and FBI/IC3 naming. FINRA states UNC6395 is also known as GRUB1, and Cloudflare uses GRUB1 in its first-party write-up. ShinyHunters and UNC6040 belong in the broader Salesforce threat context, but they should not replace UNC6395/GRUB1 as the label for this Drift-specific activity without stronger source support. 1, 5, 7, 17
| Name / Label | How To Use It | Boundary | Sources |
|---|---|---|---|
| UNC6395 | Primary label for the Salesloft Drift OAuth-token theft and Salesforce data-theft activity. | Do not apply to every Salesforce compromise or every SaaS/OAuth incident. | 1, 5 |
| GRUB1 | Alias/source label that FINRA maps to UNC6395 and Cloudflare uses for its observed incident. | Useful alias, not evidence of a separate actor in this brief. | 7, 17 |
| UNC6040 | Related Salesforce-focused threat cluster from the FBI/IC3 advisory, useful for broader context. | Separate from the Drift OAuth-token initial access path unless a source explicitly links a case. | 5 |
| ShinyHunters | Extortion-context label mentioned in public Salesforce reporting/advisory context. | Do not rename the Drift campaign as ShinyHunters based on this source set alone. | 5 |
14-Common Questions Q&A
| Question | Source-Backed Answer |
|---|---|
| Was this a Salesforce CVE? | No. The retained sources frame the issue as compromised Salesloft Drift OAuth tokens and connected-app trust, not as a Salesforce platform vulnerability. 3, 6, 8 |
| Should we call it UNC6395 or GRUB1? | Use UNC6395 as the primary name because GTIG and FBI/IC3 use it. GRUB1 is a source-backed alias from FINRA and Cloudflare. 1, 5, 7, 17 |
| Do named victims prove every Drift customer was exposed? | No. Named disclosures show concrete scoping examples, but each tenant needs its own connected-app, token, API, and object-access review. 17, 18, 19, 20 |
| Is this the same thing as the Klue incident? | No. Klue is a useful 2026 comparator for Salesforce SaaS/OAuth supply-chain risk, but this brief does not treat the two as one campaign or one actor set. 14, 15, 16 |
15-Talking Points
| Audience | Talking Point | Memorizable Quote |
|---|---|---|
| Executive | This is not just a vendor breach; it is a trusted SaaS-to-Salesforce access problem. | “The business risk is that a tool we authorized for normal revenue operations may have become a route into Salesforce data. We need to validate tokens, connected apps, and what CRM records were accessed.” |
| Salesforce / SaaS Owner | Start with connected apps and token use, not endpoint malware. | “Find every Drift/Salesloft connected app, revoke or rotate tokens, preserve Event Monitoring, and scope high-volume API queries against sensitive Salesforce objects.” |
| Legal / Privacy | Notification analysis depends on object-level access, not just whether Drift was installed. | “We need to know whether customer contacts, prospect records, notes, secrets, or regulated data were queried. The legal posture changes only after Salesforce telemetry confirms what was reachable or accessed.” |
| IR / Threat Intel | Use Drift as the prior pattern and Klue as the newer comparator. | “Salesloft Drift and Klue are not automatically the same campaign, but they show the same failure mode: trusted Salesforce integrations, OAuth tokens, API access, and downstream scoping.” |
16-Decision Ready Actions
| Target Persona | Timeframe | Decision / Action | Evidence |
|---|---|---|---|
| Executives | Today | Approve Salesforce and SaaS-integration scoping as a supply-chain identity event. | 1, 5, 7 |
| Salesforce owners | Today | Inventory Drift/Salesloft connected apps and revoke or rotate tokens before reauthorization. | 1, 3, 8 |
| SOC / IR | 24-48 hours | Preserve and review API, OAuth, event, query, and setup audit logs. | 3, 4 |
| Legal / Privacy | 24-72 hours | Assess CRM objects accessed and whether customer/prospect data triggers notification or contractual duties. | 5, 7 |
17-Exploitable Technology Risks
| Risk | Why It Matters | Defensive Priority | Sources |
|---|---|---|---|
| Over-permissioned connected apps | An integration may reach more CRM data than the workflow needs. | Least privilege, app review, OAuth policy restrictions. | 3, 8 |
| Long-lived tokens | Refresh tokens can persist beyond user password changes. | Token revocation, forced reauthorization, alerting. | 1, 3 |
| Secrets inside CRM | Attackers may search Salesforce data for credentials, tokens, and keys. | Secret hunting and rotation after data access. | 1, 4 |
| Vendor trust concentration | A single SaaS provider can create multi-customer blast radius. | Vendor-risk and SaaS-integration inventory. | 5, 7 |
19-Tier 0 Through Tier 8 Source Summary
| Tier | Trust Role | What This Tier Supports | Caveat | Sources |
|---|---|---|---|---|
| Tier 0 | Official / authoritative | FBI/IC3, Salesforce Help, and Salesforce documentation define government, platform, and connected-app boundaries. | Official sources do not publish every affected customer or full forensic detail. | 5, 6, 8 |
| Tier 1 | Primary / sector authority | Google Cloud/GTIG provides the core technical narrative; FINRA supplies sector-facing risk framing. | May use different naming conventions such as UNC6395 or GRUB1. | 1, 7 |
| Tier 2 | Practitioner research / first-party victim disclosures | Arctic Wolf and Unit 42 add response, hunting, mass-query, and secret-exposure context; Cloudflare, Zscaler, Palo Alto Networks, and Proofpoint provide named real-world impact boundaries. | Victim disclosures vary by tenant; do not assume each customer had the same objects, fields, or sensitive-data exposure. | 3, 4, 17, 18, 19, 20 |
| Tier 3 | Corroborating news | BleepingComputer makes the Salesloft breach and stolen-token path accessible to broad security teams. | Secondary to technical and official sources. | 2 |
| Tier 5 | Framework | MITRE ATT&CK links the behavior to trusted relationships, token theft, valid accounts, automated collection, and cloud/API exfiltration. | Framework mapping does not prove impact. | 9, 10, 11, 12, 13 |
| Tier 8 | Expansion research | Klue sources show the same Salesforce SaaS/OAuth supply-chain class recurring in 2026. | Comparator only; not proof of shared actors. | 14, 15, 16 |
20-About The Contributors
| Contributor | Who They Are / What They Do | Contribution & Why It Matters Here | Sources |
|---|---|---|---|
| Google Cloud / GTIG | Primary threat-intelligence publisher | Core UNC6395, campaign-window, token-theft, and Salesforce data-theft narrative. | 1 |
| FBI / IC3 | Government advisory source | Authoritative Salesforce-compromise and actor/TTP context. | 5 |
| Salesforce | Platform provider | Official Drift incident reference and connected-app trust documentation. | 6, 8 |
| Arctic Wolf / Unit 42 | Practitioner research | Hunting, scoping, secret-rotation, and response depth. | 3, 4 |
| FINRA | Sector alerting authority | Financial-sector framing, GRUB1 naming, and impact-scale context. | 7 |
| Cloudflare / Zscaler / Palo Alto Networks / Proofpoint | First-party affected-organization disclosures | Concrete real-world examples of CRM object exposure, incident boundaries, and response patterns. | 17, 18, 19, 20 |
21-Source Deconfliction
| Source Issue | Agreement / Difference | Tension or Contradiction | How To Use It |
|---|---|---|---|
| Campaign timing | Sources support August 2025 as the core Drift/UNC6395 campaign window; the May 2026 Salesforce Help date is a later official reference/update. | The Help page date can make the incident look like a new May 2026 campaign. | Keep timeline language anchored to August-September 2025 activity and use May 2026 only as a reference date. 1, 5, 6 |
| Salesforce platform boundary | The retained source set supports trusted-app/OAuth compromise, not a Salesforce core-platform CVE. | A Salesforce-data incident can be mistaken for a Salesforce software exploit. | Direct response toward connected apps, OAuth tokens, API logs, and tenant scoping rather than patch-only messaging. 3, 6, 8 |
| UNC6395 vs GRUB1 | GTIG and FBI/IC3 use UNC6395; FINRA says UNC6395 is also known as GRUB1, and Cloudflare uses GRUB1 for the actor observed in its tenant. | Different names can make the same Drift activity look like unrelated campaigns. | Treat UNC6395 and GRUB1 as source-backed labels for the same Drift activity in this brief, while keeping UNC6040 and Klue separate. 1, 5, 7, 17 |
| ShinyHunters / extortion references | FBI/IC3 discusses extortion demands allegedly from ShinyHunters in the broader Salesforce threat context, especially around UNC6040 victims. | Those references can be misread as definitive attribution for every UNC6395/Salesloft Drift victim. | Mention ShinyHunters only as a caveated extortion-context label when a source says so; do not rename the Drift campaign without stronger source support. 5 |
| Klue comparison | Klue is a later Salesforce SaaS/OAuth supply-chain comparator. | The comparator can contaminate attribution if described as the same campaign. | Use Klue to explain recurrence of the risk class, not shared infrastructure or operators. 14, 15, 16 |
| Affected-population boundary | Public first-party disclosures establish named impact at Cloudflare, Zscaler, Palo Alto Networks, and Proofpoint, but each describes a different data scope. | Named victims should not be converted into a universal exposure model for every Drift customer. | Use named examples to teach scoping patterns; rely on each tenant's connected-app and API evidence for impact. 17, 18, 19, 20 |
22-Real World Examples
These are public, first-party or source-backed examples. They are included to show the scoping pattern, not to imply every affected organization had identical data exposure.
| Example | What It Shows | Boundary | Sources |
|---|---|---|---|
| Cloudflare | Cloudflare publicly described Salesforce case-data access, customer-support context exposure, GRUB1 naming, and its own remediation/scoping process. | Cloudflare said this was a Salesforce support-data exposure, not a compromise of Cloudflare services or customer systems. | 17 |
| Zscaler | Zscaler disclosed limited Salesforce information access tied to the Salesloft Drift supply-chain incident and warned about follow-on phishing or social-engineering risk. | Zscaler framed the issue around CRM/support information exposure, not compromise of Zscaler products or production systems. | 18 |
| Palo Alto Networks | Palo Alto Networks published a response statement for a Salesforce-connected third-party Drift application incident. | The company framed the impact as isolated to CRM data and not its products, systems, or services. | 19 |
| Proofpoint | Proofpoint disclosed unauthorized Salesforce tenant access through the compromised Drift integration. | Use as a named tenant-impact example; exact exposed data must be read from the first-party notice. | 20 |
| FINRA sector alert | FINRA treated the campaign as broad enough to require financial-institution awareness and scoping, citing more than 700 impacted organizations. | Sector alerts support awareness and triage urgency; they are not a substitute for tenant-specific logs. | 7 |
23-Public Victims / Disclosure Matrix
This matrix includes public, source-backed victim or affected-organization disclosures. It is not a universal affected-customer list, and each row should be read through the reporting boundary stated by the disclosing source.
| Victim / Affected Set | Confirmation Status | Who Reported It / How Disclosed | Scope Boundary |
|---|---|---|---|
| Cloudflare | Confirmed first-party disclosure | Cloudflare publicly described the Salesloft Drift impact on Salesforce case data and used the GRUB1 actor label. 17 | Reported as Salesforce support-data exposure, not compromise of Cloudflare services or customer systems. |
| Zscaler | Confirmed first-party disclosure | Zscaler published its incident-response summary for the Salesloft Drift supply-chain incident. 18 | Reported as limited Salesforce information access with follow-on phishing/social-engineering risk. |
| Palo Alto Networks | Confirmed first-party disclosure | Palo Alto Networks published a response statement for the Salesforce-connected third-party Drift application incident. 19 | Framed as isolated to CRM data, not Palo Alto Networks products, systems, or services. |
| Proofpoint | Confirmed first-party disclosure | Proofpoint disclosed unauthorized Salesforce tenant access through the compromised Drift integration. 20 | Confirms tenant access; exact data scope should be read from the first-party notice. |
| More than 700 impacted organizations | Sector-scale reporting, not a named-victim row | FINRA described the broader impacted population in a sector-facing alert. 7 | Use for scale and urgency; do not treat as tenant-specific proof without local telemetry or direct notice. |
24-KEV and CVE Details
No CISA KEV entry or CVE is used for the Drift campaign. Response should be driven by Salesforce connected-app evidence, token revocation, and data-scoping obligations rather than vulnerability-patching workflow.
25-MITRE ATT&CK Lifecycle Mapping
| MITRE Tactic / Phase | Technique | Drift Mapping | Defender Breakpoint | Sources |
|---|---|---|---|---|
| Initial Access | T1199: Trusted Relationship | Compromised Salesloft Drift OAuth tokens created access into downstream Salesforce instances. | Inventory connected apps and revoke tokens. | 1, 5, 9, 10 |
| Credential Access | T1528: Steal Application Access Token | Stolen OAuth/refresh tokens were central to reported Salesforce data access. | Revoke tokens, force reauthorization, and review connected-app scope. | 1, 2, 10 |
| Defense Evasion | T1078: Valid Accounts | Connected-app/API activity can appear authorized until tenant logs are reviewed. | Correlate OAuth, API, user, app, source IP, and user-agent evidence. | 3, 4, 11 |
| Collection | T1119: Automated Collection | Automated Salesforce API queries and object access are described by technical sources. | Review API query logs, object access, and query-job activity. | 1, 4, 12 |
| Exfiltration | T1567: Exfiltration Over Web Service | Data theft and extortion-adjacent risk are supported by GTIG and FBI/IC3. | Scope data, preserve evidence, notify based on confirmed objects. | 1, 5, 13 |
26-Stats / Visual Snapshot
Cloudflare, Zscaler, Palo Alto Networks, and Proofpoint are retained as public examples.
FINRA cites more than 700 impacted organizations in its sector-facing alert.
The key exposure class is connected-app token abuse, not a Salesforce platform CVE.
No scheduled AI Monitoring Agent is assigned to this static page yet.
27-Additional IntelliOS Threat Intel Products on This Topic
28-Notes
| Note | Detail |
|---|---|
| No scheduled AI Agent | This page has no planned AI Agent based updates. Page Alerts therefore show a notice instead of a subscription form. |
| Token-first response | Use Salesforce connected-app, OAuth, API, and object-access evidence for scoping. Do not treat this as a patch-only vulnerability workflow. |
| Named-victim boundary | Public victim disclosures are concrete examples, but each one has a different reported data scope and should not be converted into a universal exposure model. |
29-Citations
Baseline Sources Answering The Topic Question
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 1 | Widespread Data Theft Targets Salesforce Instances via Salesloft Drift | Google Cloud / GTIG | August 26, 2025 | Primary technical threat-intelligence reporting on UNC6395, compromised Salesloft Drift OAuth tokens, Salesforce data theft, campaign timing, Drift Email scope expansion, and response recommendations. |
| 2 | Salesloft breached to steal OAuth tokens for Salesforce data-theft attacks | BleepingComputer | August 26, 2025 | Public security-media explanation of how a Salesloft breach led to stolen OAuth/refresh tokens and downstream Salesforce data-theft attacks. |
| 3 | Widespread Salesforce Data Theft via Compromised Salesloft Drift OAuth Tokens | Arctic Wolf | August 27, 2025 | Practitioner analysis on the no-Salesforce-platform-compromise boundary, customer impact, token revocation, reauthentication, and enterprise response. |
| 4 | Threat Brief: Salesloft Drift Integration Used To Compromise Salesforce Instances | Unit 42 | September 2, 2025 | Technical reporting on mass Salesforce data exfiltration, credential/secret hunting, affected objects, query-job deletion, and hunting guidance. |
| 5 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Platforms | FBI / IC3 | September 12, 2025 | Government advisory tying UNC6395 to compromised Salesloft Drift OAuth tokens, Salesforce compromise activity, extortion risk, and public TTP/indicator context. |
| 6 | Drift App (Salesloft) Unauthorized Access Incident | Salesforce Help | May 4, 2026 | Official Salesforce page for the Drift app unauthorized-access incident, used to distinguish the May 2026 page date from the August 2025 campaign window. |
| 7 | Cybersecurity Alert - Salesloft Drift AI Supply Chain Attack | FINRA | September 2025 | Sector-facing alert describing more than 700 impacted organizations, UNC6395/GRUB1 attribution, stolen OAuth tokens, and downstream Salesforce/Google Workspace/Slack implications. |
| 8 | Connected App Overview | Salesforce Help | Living documentation | Authoritative Salesforce documentation for connected apps and OAuth-based application trust relationships. |
| 9 | T1199 - Trusted Relationship | MITRE ATT&CK | Living framework | Framework mapping for adversary abuse of trusted third-party relationships. |
| 10 | T1528 - Steal Application Access Token | MITRE ATT&CK | Living framework | Framework mapping for stealing or abusing OAuth/application access tokens. |
| 11 | T1078 - Valid Accounts | MITRE ATT&CK | Living framework | Framework mapping for valid-account or trusted-token use after compromise. |
| 12 | T1119 - Automated Collection | MITRE ATT&CK | Living framework | Framework mapping for automated collection activity where Salesforce API query behavior supports it. |
| 13 | T1567 - Exfiltration Over Web Service | MITRE ATT&CK | Living framework | Framework mapping for cloud/API-mediated exfiltration patterns where supported by tenant logs. |
| 17 | The impact of the Salesloft Drift breach on Cloudflare and our customers | Cloudflare | September 2, 2025 | First-party victim disclosure with concrete Salesforce case-object exposure, GRUB1 naming, reconnaissance timeline, Bulk API exfiltration, token revocation, and customer-scoping detail. |
| 18 | Salesloft Drift Supply Chain Incident: Key Details and Zscaler's Response | Zscaler | August 30, 2025 | First-party victim disclosure describing limited Salesforce information access, affected CRM/support-case fields, response actions, and follow-on phishing/social-engineering risk. |
| 19 | Salesforce-Connected Third-Party Drift Application Incident Response | Palo Alto Networks | September 2025 | First-party affected-organization disclosure confirming the incident was isolated to CRM data and not Palo Alto Networks products or services. |
| 20 | Salesloft Drift Supply Chain Incident Response | Proofpoint | September 2025 | First-party affected-organization disclosure confirming unauthorized Salesforce tenant access through the compromised Drift integration. |
Expansion Research Sources
These sources add the Klue comparator, showing recurrence of the Salesforce SaaS/OAuth supply-chain risk class.
| # | Source | Publisher | Published | Why Used |
|---|---|---|---|---|
| 14 | An Update on the Recent Klue Security Incident | Klue | June 22, 2026 | Expansion comparator: a later Salesforce SaaS integration incident where OAuth tokens and third-party trust again created downstream CRM exposure. |
| 15 | LastPass confirms data breach in Klue supply chain attack | BleepingComputer | June 23, 2026 | Expansion comparator connecting the Klue incident to downstream customer impact and Salesforce supply-chain framing. |
| 16 | Detecting the Klue supply chain attack in Salesforce instances | Datadog Security Labs | June 2026 | Expansion comparator for Salesforce connected-app hunting, OAuth refresh-token use, and API-query detection patterns. |
30-Version Change Log
| Version | Date | Changes |
|---|---|---|
| v1.0 | June 23, 2026 | Initial static Salesloft Drift Flash Threat Intel Brief covering Salesforce OAuth token theft, UNC6395, connected-app scoping, and response priorities. |
| v1.1 | June 24, 2026 | Added reciprocal Klue linkage, quoted talking points, MITRE lifecycle naming alignment, and versioned change-log discipline to match the FortiBleed static-product standard. |
| v1.2 | June 24, 2026 | Added UNC6395/GRUB1 naming deconfliction, ShinyHunters/UNC6040 boundary language, and first-party real-world examples from Cloudflare, Zscaler, Palo Alto Networks, and Proofpoint. |
| v1.3 | June 28, 2026 | Updated the static reader to the FortiBleed standard: compact banner shell, right-side Intel Card Settings drawer, browser-saved card visibility/reorder controls, alert/share actions, and tighter card/table typography. |
| v1.4 | June 28, 2026 | Fixed banner cropping, reset AI Monitoring Agent update count to zero, added no-agent Page Alerts notice, and aligned Salesloft card count, defaults, and expanded cards with FortiBleed. |
