Salesloft Drift Supply Chain Attack Affects Hundreds of Businesses
LevelBlue Completes Acquisition of Cybereason. Learn more
Get access to immediate incident response assistance.
Get access to immediate incident response assistance.
LevelBlue Completes Acquisition of Cybereason. Learn more
LevelBlue’s Security & Compliance Team is aware of the Salesloft vulnerability affecting Drift chatbot integrations. LevelBlue, and its affiliated entities, do not utilize Drift, and Salesforce has confirmed the incident did not impact clients without this integration.
Based on current information, we confirm there has been no exposure or impact to us or our clients. Should new information arise that alters this assessment, we will provide an update directly.
For additional background on the vulnerability, Salesloft Drift, a third-party plugin for Salesforce to help automate contact and sales leads, was compromised between March to August 2025. The compromise exposed OAuth tokens that allowed the threat actor (attributed and tracked as UNC6395 by Google) to bypass authentication (including MFA) where Drift customers had integrated Drift with Salesforce. This gave the threat actors access to the Salesforce data of hundreds of organizations, including Google, Cisco, Adidas, Cloudflare, Zscaler, and Palo Alto Networks.
The initial compromise began in March when the threat actor gained access through unknown means to the Salesloft GitHub account, downloading multiple private code repositories. The attacker maintained access through at least June. Leaked information allowed the threat actor to pivot to Drift's AWS environment in early August, leveraging that access to steal OAuth tokens for Drift integrations.
The threat actor then used the OAuth tokens to access Drift's customers' Salesforce integrations, allowing the download and exfiltration of this data. In an attempt to evade forensics, the threat actor also deleted the logged records of the queries and export jobs.
As of September 9, the integration between Salesloft and Salesforce has been restored.
These types of attacks cause massive damage with only a single compromise, because they target the supply chain of major organizations instead of attacking the organizations directly. By compromising just one organization, Salesloft Drift, the threat actors were able to pivot that access to compromise hundreds of organizations.
It's vital in this day and age to take an inventory of the third-party vendors your organization relies on and document the effect on your business if one of those suppliers is compromised. Finally, make sure that your suppliers are doing their due diligence to secure themselves.
Karl Sigler is Security Research Manager, SpiderLabs Threat Intelligence at Trustwave. Karl is a 20-year infosec veteran responsible for research and analysis of current vulnerabilities, malware and threat trends at Trustwave. Follow Karl on LinkedIn.
LevelBlue is a globally recognized cybersecurity leader that reduces cyber risk and fortifies organizations against disruptive and damaging cyber threats. Our comprehensive offensive and defensive cybersecurity portfolio detects what others cannot, responds with greater speed and effectiveness, optimizes client investment, and improves security resilience. Learn more about us.