Unit 42 discovered a threat actor campaign that exploited compromised OAuth credentials in the Salesloft Drift integration to exfiltrate sensitive data from Salesforce instances between August 8-18, 2025. The attackers performed mass data extraction from Account, Contact, Case, and Opportunity records, then scanned the stolen

6m read timeFrom unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryRecommendations for OrganizationsHunting GuidanceConclusionIndicators of Compromise

Sort: