Cyber security alert: Salesloft Drift supply chain incident

4th September 2025
People meeting

Overview

Between August 8 and 18, a stealthy adversary, tracked by Google as UNC6395 is suspected to have, quietly harvested OAuth and refresh tokens via the Salesloft Drift AI chat integration with Salesforce. At first glance, the breach appeared limited.

Salesloft initially reassured that only Salesforce linked users were affected. Yet as the investigation deepened, the threat surface expanded.

Google has confirmed cases impacting other integrations other than SalesForce CRM instances with Drift Mail impacting a limited number of Google Workspace accounts including Elastic being impacted.

At the time of writing, twenty-six (26) organisations have reported being affected by the incident. This number is expected to rise, with hundreds of companies potentially at risk.

Salesforce the most widely reported on integration disabled all integrations with Salesloft as a precaution which have since been restored. Salesloft state “While the connection between systems was disabled, both Salesloft and Salesforce continued to run independently. The Salesloft Customer Success team will be reaching out to you directly to help you with data reconciliation before we can re-enable your Salesforce sync.”

Multiple organisations that use Salesloft Drift integrations have been investigating their own impact, this has resulted in Exclaimer, Palo Alto, Cloudflare, Zscaler and many other customers reporting their own investigations.

Each has advised their customers of potential risk to customer data which usually involves email addresses, contact information and support information held in the Chatbot communications and within Salesforce CRM which have been obtained. The investigations do vary depending on the reported data leaked for each organisation. It does appear that the data is limited to communications within the Chatbot only, but this may not be the case, so keep your eyes peeled for new updates from vendors impacted by the incident.

Risks by supply-chain vendor

The risks below are subject to change as each vendor progresses their investigation. The vendors listed below are known to be impacted by Salesloft Drift.

VendorCompromiseImpacted DataActionRef
ExclaimerSalesloft integration with SalesforceEmail addresses via Salesloft Drift communication.Heightened awareness of phishing attacks and social engineering attacks using information gathered.Direct to customer
Palo Alto NetworksSalesloft integration with SalesforceBusiness contact information, internal sales account and basic case data related to our customers.Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.paloaltonetworks.com/blog/2025/09/salesforce-third-party-application-incident-response/
TenableSalesloft integration with SalesforceA portion of some of our customers’ information stored in our Salesforce instance, including subject lines and initial descriptions provided by our customers when opening a tenable support case, and commonly available business contact information (such as names, business email addresses, phone numbers, and regional/location references).Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.tenable.com/blog/tenable-response-to-salesforce-and-salesloft-drift-incident
ZscalerSalesloft integration with Salesforce

Names, business email addresses, job titles, phone numbers, regional/location details.

Zscaler product licensing and commercial information,
plain text content from certain support cases [this does NOT include attachments, files, and images]

Heightened awareness of phishing attacks and social engineering attacks using information gathered.

License reuse.

Information gathered from support chats may impact Zscaler customers potential lateral movement risk if sensitive data has been shared via support communications.

https://www.zscaler.com/blogs/company-news/salesloft-drift-supply-chain-incident-key-details-and-zscaler-s-response
PagerDutySalesloft integration with SalesforceNames, phone numbers, and email addresses.Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.pagerduty.com/blog/news-announcements/salesloft-drift-data-breach-update-to-our-customers/
CloudflareSalesloft integration with Salesforce

Support cases. The subject line of the Salesforce case.

The body of the case (freeform text which may include any correspondence including keys, secrets, etc., if provided by the customer to Cloudflare).

Customer contact information (for example, company name, requestor email address and phone number, company domain name, and company country)

Reset of credentials potentially shared to Cloudflare via support cases.

Heightened awareness of phishing attacks and social engineering attacks using information gathered.

https://blog.cloudflare.com/response-to-salesloft-drift-incident/
SpyCloudSalesloft integration with SalesforceUnknown

Heightened awareness of phishing attacks and social engineering attacks using information gathered.

Be cautious of unusual communications related to your relationship with SpyCloud – for example, emails requesting or specifying payment terms.

https://spycloud.com/newsroom/salesloft-drift-incident-spycloud-response/
TaniumSalesloft integration with SalesforceNames, business email addresses, phone numbers, regional/location referencesHeightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.tanium.com/blog/salesloft-drift-data-breach-what-we-know-and-what-were-doing/
ProofpointSalesloft integration with SalesforceUnknown – TA accessed Proofpoint’s Salesforce
tenant through the compromised Drift integration and viewed certain
information stored in our Salesforce instance.
TBDhttps://www.proofpoint.com/us/blog/corporate-news/salesloft-drift-supply-chain-incident-response
RubrikSalesloft integration with SalesforceTBDTBDhttps://www.rubrik.com/blog/company/25/salesforce-connected-third-party-drift-application-supply-chain-incident-response
BeyondTrustSalesloft integration with SalesforceBased on our investigation, the threat actors had limited access to our Salesforce data and the impact was limited to Salesforce.Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.beyondtrust.com/trust-center/security-advisories/salesforce-salesloft-drift-security-incident
MegaportSalesloft integration with SalesforceTBD – Limited to names and titles, business email addresses and business phone numbersHeightened awareness of phishing attacks and social engineering attacks using information gathered.https://trust.megaport.com/?tcuUid=f3ee3f57-2b3c-4b77-96b2-aad93acd0c47
HeapSalesloft integration with SalesforceTBD – Confirmed that a subset of records within Heap’s
Salesforce instance was accessed by the threat actor.
Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://trust.contentsquare.com/?tcuUid=2c81adf8-1e70-4130-9d1d-94966df59058
BugcrowdSalesloft integration with SalesforceTBD – Identified evidence that certain information stored within our Salesforce instance
was accessed by an unauthorised user.
TBDhttps://www.bugcrowd.com/blog/bugcrowd-response-to-salesforce-linked-third-party-drift-application-security-event/
JFrogSalesloft integration with SalesforceTBD – “investigation is ongoing, we have discovered that some
data stored in JFrog’s Salesforce instance was accessed by
leveraging illegitimate access to the Drift Application.”
Following security best practices, we recommend revocation and rotation of credentials/keys/secrets and monitoring your environment for any unusual activity.https://jfrog.com/help/r/salesforce-data-incident-identified-linked-to-third-party-salesloft-drift/salesforce-data-incident-identified-linked-to-third-party-salesloft-drift
WorkivaSalesloft integration with SalesforceWithin Salesforce – names, email addresses, phone numbers, and support ticket content.Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.bleepingcomputer.com/news/security/saas-giant-workiva-discloses-data-breach-after-salesforce-attack/
AkamaiSalesloft integration with SalesforceLimited service support tickets
Akamai corporate email addresses and phone numbers.
Customer corporate email addresses and phone numbers.
Pseudonymised email addresses. A services-related support case description which
included one outdated and inactive API token,
and one active API token.

Heightened awareness of phishing attacks and social engineering attacks using information gathered.

Rotate API tokens.

Direct to customer
CyberarkSalesloft integration with SalesforceThe data accessed by the threat actor was limited to that contained in our Salesforce CRM, and may include business contact information, account and conversation metadata,
and summary fields.
Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.cyberark.com/resources/blog/salesloft-drift-incident-overview-and-cyberarks-response                   
UnknownSalesloft integration with Drift Email – Google WorkspaceSmall number of Google Workspace accounts.Google recommend s organisations take immediate action to review all third-party integrations connected to their Drift instance, revoke and rotate credentials for those applications, and investigate all connected systems for signs of unauthorised access.https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift
CatoSalesloft integration with SalesforceThe exposed Salesforce data included: customer business contact information, company attributes, and basic customer case information.Review inbound communications carefully.
Validate senders independently.
Protect login credentials.
https://www.catonetworks.com/blog/cato-networks-statement-on-salesforce-salesloft-drift-incident/
EskerSalesloft integration with SalesforcePotential data: names, business email addresses, job titles, phone numbers, plain text content from support tickets.Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.esker.com/blog/esker-news-and-culture/salesloft-and-drift-oauth-incident-affecting-salesforce-data-what/
Black DuckSalesloft integration with SalesforceExfiltrated data includes: names,
business email addresses, job titles, phone numbers, regional/location details, service arrangement data, plain text content from support cases.
Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://community.blackduck.com/s/article/Salesloft-Drift-Breach-Impact-on-Black-Duck-Update-to-Our-Customers
NutanixSalesloft integration with SalesforceThe impacted data was limited to customer support case records within our Salesforce environment that contained certain fields that primarily
included business contacts and/or information relating to the case such as the subject field of the support case, the
description field of the support case, and in limited instances,
support case correspondence.
Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.nutanix.com/blog/third-party-salesloft-drift-application-incident-response-our-impact-and-action
QualysSalesloft integration with SalesforceVague – limited access to Salesforce informationHeightened awareness of phishing attacks and social engineering attacks using information gathered.https://blog.qualys.com/misc/2025/09/06/salesloft-drift-supply-chain-incident
DynatraceSalesloft integration with SalesforceSalesforce no case information. Limited to business contact information, including first and last names of customer contacts and company identifiers.Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.dynatrace.com/news/blog/salesloft-drift-incident-dynatraces-response/
FastlySalesloft integration with SalesforceWas isolated to our Salesforce instance and the data accessed was limited to case subjects, descriptions, and contact details.Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.fastlystatus.com/incident/377884
ElasticSalesloft integration with Drift Email – Google WorkspaceAfter scanning the contents of this inbox, we identified a small number of inbound emails that included potentially valid credentials. For each of these cases where we identified a potential credential leak, we notified customers through existing support channels. If you did not receive notice from us, we did not identify you as an affected customer.Rotate credentials where affected. Heightened awareness of phishing attacks and social engineering attacks using information gathered.https://www.elastic.co/blog/elastic-update-salesloft-drift-security-incident

    • Continue to monitor for new incident response updates from your vendors.

    • Increase phishing awareness for employees impacted.

    • Investigate if your support case or communication data may contain sensitive data. In some cases, you may have shared credentials, API keys, configuration details, or other sensitive data within chats.

    • Contact your vendors if you’re unsure if they’re impacted.

    • Revoke and rotate all OAuth tokens associated with Drift and credentials.

    • Investigate audit logs within Salesforce and any applications related to Salesloft Drift.

    • Enforce least privilege

    • If directly impacted assess the data accessed. Review all customer support case data with your third-party providers to identify what sensitive information may have been exposed. Look for cases containing credentials, API keys, configuration details, or other sensitive data that customers may have shared.

Zensec – here to help

References: