22.2 C
New York
Saturday, September 6, 2025

Salesloft Takes Drift Offline After OAuth Token Theft Hits Lots of of Organizations


Sep 03, 2025Ravie LakshmananInformation Breach / Menace Intelligence,

Salesloft Takes Drift Offline After OAuth Token Theft Hits Lots of of Organizations

Salesloft on Tuesday introduced that it is taking Drift briefly offline “within the very close to future,” as a number of firms have been ensnared in a far-reaching provide chain assault spree concentrating on the advertising and marketing software-as-a-service product, ensuing within the mass theft of authentication tokens.

“This may present the quickest path ahead to comprehensively overview the appliance and construct extra resiliency and safety within the system to return the appliance to full performance,” the corporate stated. “In consequence, the Drift chatbot on buyer web sites is not going to be accessible, and Drift is not going to be accessible.”

The corporate stated its high precedence is to make sure the integrity and safety of its methods and prospects’ information, and that it is working with cybersecurity companions, Mandiant and Coalition, as a part of its incident response efforts.

The event comes after Google Menace Intelligence Group (GTIG) and Mandiant disclosed what it stated was a widespread information theft marketing campaign that has leveraged stolen OAuth and refresh tokens related to the Drift synthetic intelligence (AI) chat agent to breach prospects’ Salesforce situations.

“Starting as early as August 8, 2025, by not less than August 18, 2025, the actor focused Salesforce buyer situations by compromised OAuth tokens related to the Salesloft Drift third-party software,” the corporate stated final week.

Audit and Beyond

The exercise has been attributed to a risk cluster dubbed UNC6395 (aka GRUB1), with Google telling The Hacker Information that greater than 700 organizations could have been probably impacted.

Whereas it was initially claimed that the publicity was restricted to Salesloft’s integration with Salesforce, it has since emerged that any platform built-in with Drift is probably compromised. Precisely how the risk actors gained preliminary entry to Salesloft Drift stays unknown at this stage.

The incident has additionally prompted Salesforce to briefly disable all Salesloft integrations with Salesforce as a precautionary measure. A number of the companies which have confirmed being impacted by the breach are as follows –

“We consider this incident was not an remoted occasion however that the risk actor meant to reap credentials and buyer info for future assaults,” Cloudflare stated.

“Provided that a whole lot of organizations have been affected by this Drift compromise, we suspect the risk actor will use this info to launch focused assaults in opposition to prospects throughout the affected organizations.”

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles