Dissecting the Salesloft Drift Breach
In August 2025, a major cyberattack targeted Salesloft Drift, a conversational marketing and sales engagement platform integrated with Salesforce and numerous other enterprise systems. Attackers exploited compromised OAuth tokens to gain unauthorised access to hundreds of customer instances, exfiltrating sensitive data such as AWS access keys, passwords, Snowflake tokens, and CRM records. Over 700 organisations were potentially affected, including Cloudflare, Google Workspace, PagerDuty, Palo Alto Networks, Proofpoint, SpyCloud, Tanium, and Zscaler. This incident underscores the risks posed by supply-chain attacks in highly integrated SaaS environments.
Source: CyberSecBrief













