In August 2025, attackers exploited a compromise of Salesloft's GitHub account to steal OAuth tokens from the Drift chatbot integration, enabling access to Salesforce data of over 700 organizations. Major security vendors including Qualys, Tenable, Proofpoint, Black Duck, BeyondTrust, Cloudflare, and Palo Alto Networks were affected, with attackers exfiltrating support case data, business contacts, and internal notes. The breach was contained after Drift was taken offline, credentials were rotated, and integrations were restored following forensic investigation.
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Gainsight said it was investigating malicious activity affecting Gainsight-published applications on Salesforce, and stated the issue originated from the apps' external connection rather than a Salesforce platform flaw. In response, Salesforce revoked active access and refresh tokens tied to Gainsight-published applications and temporarily removed those apps from AppExchange, while Zendesk and HubSpot suspended Gainsight connector access as a precaution.
A group calling itself Scattered LAPSUS$ Hunters publicly claimed it had hacked Salesforce-related environments and threatened to leak data allegedly tied to more than 700 companies unless paid, setting an October 10, 2025 deadline. Salesforce said it was aware of the extortion attempts but described them as tied to past or unsubstantiated incidents and said there was no indication the Salesforce platform itself had been compromised.
Initial story creation
Qualys confirmed that its Salesforce data was compromised as part of the Salesloft-Drift cyberattack. This adds a newly disclosed affected organization to the supply-chain incident's impact.
Proofpoint published a corporate incident response post بشأن the Salesloft Drift supply-chain incident. This represents a substantive disclosure/response related to the incident and establishes the story by at least the publication date.
Google confirmed a potential compromise involving Salesloft Drift customer authentication tokens, indicating the issue may have affected all customer tokens. This represents an earlier and broader impact disclosure in the Salesloft Drift supply-chain incident.
8 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcecybernews.com
Open sourcethecyberthrone.in
Open sourcetrustwave.com
Open sourcescworld.com
Open sourcecyberpress.org
Open sourceproofpoint.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.