Desk live·
ForensicPost
Cloud/Method/File 25-0820

Salesloft Intrusion Began in March and Stayed Dormant Until August

The Salesloft intrusion began with a source-repository compromise around March 2025, then went quiet until August. Dormancy defeats the assumption that detection windows are short.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
TargetIncident response practice
ActorUNC6395
S. Rosler11 min readConfidence: medium2 sources reviewed

Analysis of the Salesloft incident filed at 25-0818 describes a sequence: a GitHub compromise between March and June 2025, a dormant period, then active exploitation from 8 to 18 August.

The ten days of theft are what everyone remembers. The five months before them are the more instructive part.

Dormancy Is A Deliberate Operational Choice

An intruder who acts immediately risks colliding with active investigation of whatever produced the initial access. An intruder who waits benefits from log rotation, staff turnover, and the closure of whatever ticket the original anomaly generated.

By August, the evidence that would have connected the token theft to the March repository compromise had largely aged out — the retention problem this desk filed at 26-0620.

It Breaks The Metric Everyone Reports

Dwell time is conventionally measured from first access to detection, and this desk records it in every case card. On that measure this incident ran roughly five months.

But the harm occupied ten days at the end. A single dwell figure conflates a long quiet period with a short intense one, and an organisation optimising to reduce mean dwell time may be optimising against the wrong phase.

What It Argues For

Retention long enough to reconstruct backwards from a discovered theft — which means keeping authentication and access logs longer than the dwell time you expect, not longer than the dwell time you have previously seen. The corpus records at 26-0203 how closely a long quiet intrusion resembles legitimate account usage, and at 25-0807 how much turns on somebody noticing early.

A source repository compromise that looks contained in March is not contained if the credentials taken from it are still valid in August. Rotation after a repository incident is the control that would have severed this chain, and it is routinely scoped too narrowly.

How we reported this

This is an analysis file built on published incident research, listed below. Phase dates are as reported by the researchers. See 25-0818 for the incident. Corrections: corrections@forensicpost.com.

Sources
  1. Reviewing the Salesforce–Salesloft Drift OAuth supply chain breachAnomali
  2. Anatomy of the Salesloft breach — detection, response, and lessons learnedPermiso
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary