Desk live·
ForensicPost
Cloud/Tokens/File 25-0818

One Integration, Seven Hundred Customer Environments

Attackers stole OAuth refresh tokens from Salesloft’s Drift integration and used them to query the Salesforce instances of more than 700 organisations over ten days in August 2025.

Constructed geometry · not a chart of case data
TargetSalesloft Drift integration
ActorUNC6395
D. Kennedy14 min readConfidence: high3 sources reviewed

Attackers tracked as UNC6395 stole OAuth refresh tokens belonging to Salesloft’s Drift integration with Salesforce. Those tokens permitted Drift to query Salesforce on behalf of its customers. Between 8 and 18 August 2025 the attackers used them to systematically query and export records from more than 700 organisations.

Named affected organisations include Cloudflare, Google, PagerDuty, Palo Alto Networks, Proofpoint, SpyCloud, Tanium and Zscaler. On 20 August, Salesloft and Salesforce revoked all Drift OAuth tokens and the application was removed from the AppExchange pending investigation.

This Is The File Every OAuth Argument In This Database Points At

This desk filed the mechanism at 26-0611 — a vendor’s token store is a key ring for its entire integrated customer base — and the technique for obtaining consent at 26-0607. This is that mechanism at its largest observed scale.

Nothing was exploited in any customer environment. The tokens were used exactly as designed, from infrastructure the customer’s logs expected them to come from, performing queries the integration was authorised to perform.

The Victim List Is Unusually Sophisticated

The affected organisations include several of the most capable security companies in the industry. That is worth stating plainly, in the same spirit as the Google file at 26-0619: this was not a failure of security maturity.

A customer cannot detect misuse of a token they granted, held by a third party, used from that third party’s infrastructure. The control was never on their side of the boundary.

What A Customer Could Actually Have Done

Scoped the grant more tightly than the integration requested. Set an expiry. Monitored export volume from connected applications rather than only authentication events. Each is available in the platform and each is commonly left at the permissive default, for the reasons set out at 26-0607.

How we reported this

Compiled from published vendor research and company disclosures, listed below. Organisation counts and the victim list are as reported and as confirmed by the companies concerned. We have not reviewed tenant logs. Corrections: corrections@forensicpost.com.

Sources
  1. Threat brief: Salesloft Drift integration used to compromise Salesforce instancesUnit 42, Palo Alto Networks
  2. Salesloft Drift–Salesforce breach (UNC6395): why Salesforce OAuth integrations are a growing riskAppOmni
  3. Cybersecurity alert — Salesloft Drift AI supply chain attackFINRA
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary