Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations

Salesloft Takes Drift Offline After OAuth Token Theft Hits Hundreds of Organizations

Posted on September 3, 2025September 3, 2025 By CWS

Sep 03, 2025Ravie LakshmananData Breach / Menace Intelligence,
Salesloft on Tuesday introduced that it is taking Drift quickly offline “within the very close to future,” as a number of corporations have been ensnared in a far-reaching provide chain assault spree concentrating on the advertising and marketing software-as-a-service product, ensuing within the mass theft of authentication tokens.
“It will present the quickest path ahead to comprehensively evaluate the appliance and construct extra resiliency and safety within the system to return the appliance to full performance,” the corporate mentioned. “Consequently, the Drift chatbot on buyer web sites is not going to be accessible, and Drift is not going to be accessible.”
The corporate mentioned its high precedence is to make sure the integrity and safety of its techniques and clients’ knowledge, and that it is working with cybersecurity companions, Mandiant and Coalition, as a part of its incident response efforts.

The event comes after Google Menace Intelligence Group (GTIG) and Mandiant disclosed what it mentioned was a widespread knowledge theft marketing campaign that has leveraged stolen OAuth and refresh tokens related to the Drift synthetic intelligence (AI) chat agent to breach clients’ Salesforce cases.
“Starting as early as August 8, 2025, via no less than August 18, 2025, the actor focused Salesforce buyer cases via compromised OAuth tokens related to the Salesloft Drift third-party software,” the corporate mentioned final week.

The exercise has been attributed to a menace cluster dubbed UNC6395 (aka GRUB1), with Google telling The Hacker Information that greater than 700 organizations might have been probably impacted.
Whereas it was initially claimed that the publicity was restricted to Salesloft’s integration with Salesforce, it has since emerged that any platform built-in with Drift is probably compromised. Precisely how the menace actors gained preliminary entry to Salesloft Drift stays unknown at this stage.
The incident has additionally prompted Salesforce to quickly disable all Salesloft integrations with Salesforce as a precautionary measure. Among the companies which have confirmed being impacted by the breach are as follows –

“We consider this incident was not an remoted occasion however that the menace actor supposed to reap credentials and buyer data for future assaults,” Cloudflare mentioned.
“Provided that tons of of organizations have been affected via this Drift compromise, we suspect the menace actor will use this data to launch focused assaults towards clients throughout the affected organizations.”

The Hacker News Tags:Drift, Hits, Hundreds, OAuth, Offline, Organizations, Salesloft, Takes, Theft, Token

Post navigation

Previous Post: Cloudflare Confirms Data Breach, Hackers Stole Customer Data from Salesforce Instances
Next Post: CISA Adds TP-Link and WhatsApp Flaws to KEV Catalog Amid Active Exploitation

Related Posts

Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362 Cisco Warns of New Firewall Attack Exploiting CVE-2025-20333 and CVE-2025-20362 The Hacker News
GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection GootLoader Malware Uses 500–1,000 Concatenated ZIP Archives to Evade Detection The Hacker News
Silver Fox Targets India and Russia with ABCDoor Malware Silver Fox Targets India and Russia with ABCDoor Malware The Hacker News
Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code Extension Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code Extension The Hacker News
New China-Linked Hacker Group Hits Governments With Stealth Malware New China-Linked Hacker Group Hits Governments With Stealth Malware The Hacker News
MirrorFace Targets Japan and Taiwan with ROAMINGMOUSE and Upgraded ANEL Malware MirrorFace Targets Japan and Taiwan with ROAMINGMOUSE and Upgraded ANEL Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft
  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Vulnerability in PraisonAI Exploited Within Hours
  • Langflow Vulnerability Exploited for AWS Key Theft
  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark