Drift chatbot tokens opened Salesforce data at hundreds of firms
Attackers did not break into Salesforce. They stole the keys a third-party AI chat agent had been given to it.
By The Agentic Times ·

A threat actor used OAuth tokens stolen from Salesloft's Drift AI chat agent to access Salesforce instances at hundreds of organisations in August 2025, in one of the largest supply-chain incidents involving an AI-powered SaaS integration.
Google's Threat Intelligence Group, which tracked the actor as UNC6395, said the campaign ran from about 8 to 18 August. The attacker used the Drift integration's tokens to run queries against customer Salesforce data, focusing on support cases, and then searched the results for credentials such as AWS keys, Snowflake tokens and passwords. Google said more than 700 organisations were potentially affected.
Drift is a chat agent that many companies embed on their websites to qualify leads, and it connects to Salesforce to write and read customer records. Salesloft, which owns Drift, said the attacker had first compromised its GitHub account and used that access to obtain the tokens. Salesforce and Salesloft revoked all Drift tokens and temporarily removed the integration from the AppExchange.
Cloudflare, Zscaler, Palo Alto Networks and others published disclosures confirming that customer contact details and support case text had been accessed. Cloudflare said it rotated over a hundred tokens found in its case data.
The incident showed how an AI agent's integrations can become the weakest link in an organisation's data perimeter, even when the agent itself is never manipulated. Google and the affected companies recommended auditing third-party OAuth grants and treating support case content as sensitive data.
Sources
- cloud.google.comhttps://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift
- blog.cloudflare.comhttps://blog.cloudflare.com/response-to-salesloft-drift-incident/
