IncidentsDrift chatbot tokens opened Salesforce data at hundreds of firms
Attackers did not break into Salesforce. They stole the keys a third-party AI chat agent had been given to it.
27 Aug 2025
Attackers tracked as UNC6395 used OAuth tokens stolen from the Drift AI chat agent integration to query Salesforce instances at hundreds of organisations, harvesting credentials stored in support cases.
Occurred 8 August 2025 · Disclosed 20 August 2025 · Record updated 13 September 2026
Google said more than 700 organisations were potentially affected; Cloudflare, Zscaler and Palo Alto Networks confirmed exposure of customer contact data and support case content.
IncidentsAttackers did not break into Salesforce. They stole the keys a third-party AI chat agent had been given to it.
27 Aug 2025