Salesforce is under intense scrutiny following a series of cyberattacks that led to the exposure of customer data through a third-party application, Salesloft, which utilized OAuth tokens. Multiple lawsuits, including several seeking class action status, have been filed in Northern California against Salesforce and its users, alleging that the company failed to implement adequate cybersecurity measures to protect personally identifiable information (PII). Plaintiffs claim that the breach has resulted in victims being at heightened risk for identity theft and fraud, with some already experiencing concrete injuries. The lawsuits demand that Salesforce disclose the full extent of the compromised information and adopt stronger security practices to prevent future incidents. Salesforce has publicly denied that its own systems were compromised, asserting that the breaches were not due to shortcomings in its platform. However, the attacks were confirmed by Google Threat Intelligence Group, which identified the theft of OAuth tokens from the Salesloft Drift app as the attack vector. The FBI has issued warnings about the increasing trend of compromised accounts, highlighting the broader risk to cloud platforms like Salesforce. Security experts from AppOmni, Google Cloud Mandiant, and Okta have weighed in, noting that while Okta's brand was misused in some attack variants, its platform was not directly affected. The breaches have led to significant reputational damage for Salesforce, with many organizations—some of them major brands—reporting large-scale data exfiltration and subsequent ransom demands. Some affected companies have been transparent about their use of Salesforce as the attack target, while others have referred more vaguely to third-party applications. Media reports have widely suggested that Salesforce was the underlying system in many of these incidents. The lawsuits allege that Salesforce's trust-first culture has been undermined by these events, and that the company could have done more to secure the exploited parts of its platform. Victims are now advised to monitor their financial accounts and credit reports closely. The legal actions seek both compensation for damages and injunctive relief to force improvements in Salesforce's security posture. The ongoing litigation and public scrutiny have created a trust crisis for Salesforce, as customers and regulators demand greater transparency and accountability. The incident underscores the risks associated with third-party integrations and the importance of robust OAuth token management. Salesforce's response and the outcomes of these lawsuits are likely to have significant implications for the broader SaaS and cloud services industry.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
By September 26, reports said Salesforce was facing multiple lawsuits in connection with the Salesloft breach. This represented a further escalation from an earlier potential class action to several active legal claims.
Reporting said Salesforce was facing a potential class action lawsuit tied to the cyberattack fallout and customer trust concerns. This marked the first referenced legal escalation in the story.
A breach involving Salesloft led to broader scrutiny of Salesforce's security posture, with reporting describing Salesforce as facing a growing trust problem after cyberattack-related fallout. The incident appears to be the underlying event driving subsequent legal action.
Google Threat Intelligence Group published research describing UNC6395 as conducting a widespread data theft campaign against Salesforce customer instances using compromised OAuth tokens tied to the Salesloft Drift platform. The report said the actor exported Salesforce data, searched it for secrets such as AWS keys and passwords, and warned Drift-integrated organizations to investigate exposure and rotate any exposed credentials.
4 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcetheregister.com
Open sourcezdnet.com
Open sourceaustinlarsen.me
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.