Quick Takeaways
-
Drift Software Compromise: Salesloft is temporarily disabling Drift due to a supply chain attack that has led to the theft of authentication tokens affecting multiple companies.
-
Incident Investigation: The company is collaborating with cybersecurity firms Mandiant and Coalition to enhance security and assess the impact on customer data.
-
Widespread Impact: The attack, attributed to threat cluster UNC6395, has potentially affected over 700 organizations, with integrations between Drift and various platforms at risk.
- Precautionary Measures: Salesforce has disabled all Salesloft integrations to mitigate risks, raising concerns about future targeted attacks on affected organizations.
Salesloft Takes Drift Offline Amid OAuth Token Theft
Salesloft announced a significant decision on September 3, 2025, to take its Drift service offline. This action comes after numerous companies fell victim to a large-scale supply chain attack that compromised authentication tokens. The company aims to enhance security and resilience within its application. Consequently, the Drift chatbot will be unavailable on customer websites. Salesloft has prioritized the integrity of its systems and customer data, collaborating with cybersecurity firms like Mandiant and Coalition to manage the crisis effectively.
The origin of the compromise traces back to activities between August 8 and August 18, 2025. Cybersecurity experts from Google Threat Intelligence Group and Mandiant linked the attack to a threat cluster known as UNC6395 (or GRUB1), suggesting that over 700 organizations experienced potential breaches. Initially, experts thought the threat was confined to Salesloft’s integration with Salesforce. However, it has since become evident that any platform connected to Drift might also be at risk. Salesforce has opted to temporarily disable all Salesloft integrations as a precaution.
Potential Consequences and Future Implications
The implications of this breach extend beyond immediate theft. Experts believe that the threat actor’s intention was to gather credentials and customer information for future cyberattacks. This theory raises concerns about widespread targeting, as many organizations must now evaluate their own security protocols in light of this incident. The exposed data may play a significant role in future attacks against clients across the affected organizations.
As businesses navigate this evolving landscape, the need for robust cybersecurity measures becomes increasingly clear. The Drift compromise underscores vulnerabilities in software-as-a-service models, highlighting the necessity for companies to adopt proactive security strategies. Cybersecurity experts urge organizations to reassess their data protection measures and remain vigilant against emerging threats in a rapidly changing digital environment.
Stay Ahead with the Latest Tech Trends
Dive deeper into the world of Cryptocurrency and its impact on global finance.
Access comprehensive resources on technology by visiting Wikipedia.
DataProtection-V1
