Skip to content
Supply chainContained

Salesloft Drift OAuth supply-chain breach hits Cloudflare, Palo Alto Networks, Zscaler and others

A wave of security and technology firms disclosed data theft after attackers tracked as UNC6395 abused stolen OAuth tokens from Salesloft's Drift chatbot integration to export data from hundreds of connected Salesforce environments.

Victim
Salesloft Drift / Salesforce customers (UNC6395 supply-chain wave)

Between roughly 9 and 17 August 2026, an intrusion set that Google/Mandiant tracks as UNC6395 systematically abused stolen OAuth tokens belonging to Salesloft's Drift โ€” an AI chatbot that integrates with Salesforce โ€” to reach into the Salesforce environments of hundreds of organisations. Starting on 2 September 2026, a wave of major security and technology companies publicly confirmed that their data had been swept up, turning a single third-party integration into one of the year's largest supply-chain compromises.

The named victims read like a roster of the security industry itself, including Cloudflare, Palo Alto Networks, Zscaler, SpyCloud, Tanium, Proofpoint and, in follow-on disclosures, Workiva โ€” with reporting placing the total number of affected organisations at more than 700. In most cases the companies stressed that the exposure was confined to data stored in Salesforce โ€” principally business contact information, support-case text, and account records โ€” and did not touch their core products, source code or customer-facing infrastructure.

A credential-harvesting operation

Investigators characterised the campaign as a credential-harvesting exercise rather than opportunistic data theft. The attackers used automated Salesforce Object Query Language (SOQL) queries, bulk exports and custom user-agent strings to blend in, then combed the exfiltrated support-case text for secrets โ€” plaintext AWS keys, VPN credentials, Snowflake tokens and similar material that could unlock deeper follow-on intrusions. That focus made the incident dangerous well beyond the contact records themselves.

Containment across the ecosystem

In response, Salesloft and Salesforce revoked the affected Drift tokens and disabled the integration while the investigation proceeded, and individual victims rotated exposed secrets and notified customers. Because the intrusion was scoped to Salesforce data accessed through a now-revoked integration โ€” and no victim reported compromise of its production systems โ€” the campaign was broadly assessed as contained, even as the sheer number of downstream organisations and the credential-harvesting angle kept remediation work running for weeks. The activity was later publicly linked by extortion actors operating under the ShinyHunters banner.

Timeline

  1. UNC6395 begins abusing stolen OAuth tokens tied to Salesloft's Drift integration to query and export data from connected Salesforce instances; the activity runs through mid-August.

  2. Zscaler and Palo Alto Networks confirm that customer contact details and support-case data were exposed via their Salesforce instances through the Salesloft Drift compromise.

  3. Cloudflare, SpyCloud and further firms disclose exposure of Salesforce data via the same campaign; reporting puts the number of affected organisations at more than 700.

  4. Workiva and additional victims are named; investigators warn that stolen support-case text is being combed for embedded credentials to enable follow-on attacks.

Sources

  1. helpnetsecurity.comhttps://www.helpnetsecurity.com/2025/09/02/zscaler-palo-alto-networks-spycloud-among-the-affected-by-salesloft-breach/
  2. therecord.mediahttps://therecord.media/salesloft-drift-breach-cloudflare-zscaler-palo-alto-networks
  3. cyberscoop.comhttps://cyberscoop.com/salesloft-drift-attacks-cloudflare-palo-alto-networks-zscaler/
  4. securityweek.comhttps://www.securityweek.com/security-firms-hit-by-salesforce-salesloft-drift-breach/

Related incidents