4 Sources
[1]
Salesloft says Drift customer data thefts linked to March GitHub account hack | TechCrunch
Salesloft said a breach of its GitHub account in March allowed hackers to steal authentication tokens that were later used in a mass-hack targeting several of its big tech customers. Citing an investigation by Google's incident response unit Mandiant, Salesloft said on its data breach page that
[2]
Zscaler data breach exposes customer info after Salesloft Drift compromise
Cybersecurity company Zscaler warns it suffered a data breach after threat actors gained access to its Salesforce instance and stole customer information, including the contents of support cases. This warning follows the compromise of Salesloft Drift, an AI chat agent that integrates with
[3]
Zscaler says it suffered data breach following Salesloft Drift compromise
The attackers moved in after compromising Salesloft's Drift platform We can now add Zscaler to the growing list of Salesloft customers who suffered a third-party cyberattack and lost sensitive customer information after it confirmed data was taken. In the announcement, Zscaler explained it was a
[4]
Zscaler: Salesloft Drift breach exposed customer data
Zscaler warns customer data exposed after Salesforce integration hack. Zscaler, a cybersecurity firm, has issued a warning regarding a data breach affecting its customers. The breach stemmed from a compromise of its Salesforce instance following a supply-chain attack targeting Salesloft Drift.
Share
Copy Link
A supply-chain attack on Salesloft's Drift platform has led to data breaches at several tech companies, including Zscaler. The incident, linked to a March GitHub account hack, has raised concerns about cybersecurity practices and data protection.
In a significant cybersecurity incident, Salesloft's AI-powered marketing platform, Drift, has been compromised, leading to a supply-chain attack affecting numerous high-profile tech companies. The breach, which began with a hack of Salesloft's GitHub account in March, has exposed sensitive customer data and raised questions about the security practices of affected organizations
1
.
Source: TechRadar
The attack unfolded over several months, with hackers gaining access to Salesloft's GitHub account in March and conducting reconnaissance activities until June. During this time, they downloaded content from multiple repositories, added a guest user, and established workflows
1
. The prolonged access raises concerns about Salesloft's security posture and detection capabilities.Several prominent tech companies have been affected by the breach, including:
The full extent of the impact remains unknown, with potentially more affected companies yet to be identified
1
.
Source: BleepingComputer
The attackers exploited OAuth tokens associated with Drift's integration with Salesforce. This allowed them to access Salesforce instances of Drift's customers and exfiltrate sensitive data, including:
2

Source: TechCrunch
Google's Threat Intelligence Group (GTIG) has attributed the attack to a hacking group known as UNC6395
2
. However, some cybersecurity publications and researchers have linked the breach to the prolific hacking group ShinyHunters, known for their extortion attempts1
.Related Stories
The Salesloft Drift compromise has also impacted Drift Email, used for managing email replies and organizing CRM and marketing automation databases. Attackers have reportedly used stolen OAuth tokens to access Google Workspace email accounts
2
.Affected companies are taking steps to mitigate the risks associated with the breach:
3
.2
.4
.This incident highlights the critical importance of supply-chain security and the potential risks associated with third-party integrations. Organizations are advised to review their security practices, particularly concerning OAuth token management and access controls for cloud-based services.
Summarized by
Navi
[1]
[2]
[4]
27 Aug 2025•Technology

20 Apr 2026•Technology

26 Sept 2025•Technology

1
Technology

2
Technology

3
Policy and Regulation
