Zscaler Confirms Breach Amid Expanding Salesloft Drift Cyberattack

Listen to this Post

Featured Image

Introduction

A fresh wave of cyberattacks is rattling the tech industry, this time tied to the Salesloft Drift breach that has been spreading across multiple platforms. Zscaler, a global cybersecurity leader, has now confirmed it was caught up in the campaign. While the company emphasized that its core infrastructure and services remain untouched, attackers exploited OAuth tokens to peek into Salesforce data. What initially looked like a contained Salesforce-linked compromise is now proving to be much broader, with Google also revealing that its Workspace users were affected through Drift integrations. The incident highlights just how dangerous interconnected SaaS ecosystems can be when trust in third-party integrations is abused.

Zscaler’s Breach and Initial Response

Zscaler disclosed that unauthorized actors gained access to Drift credentials connected to its Salesforce environment. This allowed limited visibility into company-related Salesforce records, though the vendor stressed there was no compromise of its primary products or services.

The exposed data included:

Business contact information (names, emails, job titles, phone numbers)

Location details

Zscaler product licensing and commercial data

Salesforce support case content

To mitigate risks, Zscaler swiftly revoked Drift’s Salesforce access, rotated tokens, reinforced authentication, and launched a joint investigation with Salesforce. The company also warned customers to be cautious of phishing or social engineering attempts.

The Bigger Picture: Google’s Findings

The attack has proven to be far wider than initially expected. Google’s Threat Intelligence Group (GTIG) and Mandiant reported that attackers also compromised OAuth tokens connected to Drift Email integrations. On August 9, 2025, these stolen tokens were used to access a small number of Google Workspace accounts.

Google clarified that:

The breach was not a compromise of Workspace itself.

Only accounts integrated with Salesloft Drift were exposed.

No broader customer accounts were accessible.

In response, Google revoked Drift Email tokens, disabled Workspace integrations, and urged users to rotate credentials and review their logs for suspicious activity.

UNC6395 and Data Exfiltration

Investigators traced the attack to a threat group labeled UNC6395, which stole OAuth tokens between August 8–18, 2025. Their campaign focused on exfiltrating Salesforce data and harvesting sensitive credentials, including AWS keys and Snowflake tokens.

Evidence shows the attackers even deleted query logs to cover their tracks, making detection more difficult. Google, Mandiant, and Salesloft have advised all customers to assume their OAuth tokens are compromised and to rotate them immediately.

Salesloft and Salesforce’s Damage Control

Salesloft confirmed that hackers used Drift’s Salesforce integrations to pull customer data such as Cases, Accounts, and Opportunities. On August 20, 2025, Salesloft revoked all Drift–Salesforce connections and reassured non-Salesforce customers they were unaffected.

Salesforce echoed the message, stating that only a small fraction of its customer base was impacted. The company quickly revoked tokens, pulled Drift from AppExchange, and notified affected organizations.

What Undercode Say:

The Zscaler breach, while not catastrophic, is a perfect case study in how modern cybersecurity risks are no longer limited to direct attacks. Instead, the battlefield has shifted to supply chain-style breaches through SaaS integrations. Here’s why this matters:

1. OAuth Tokens as a New Attack Surface

OAuth was designed to simplify authentication, but its widespread adoption makes it a goldmine for attackers. Once tokens are compromised, they bypass traditional login defenses. This case proves how a single integration can open doors across multiple ecosystems.

2. The Illusion of Containment

Initially, Zscaler claimed limited exposure, but as Google and Mandiant revealed, the scope went beyond Salesforce. This shows how early assurances in cybersecurity breaches often underplay the reality, either due to lack of visibility or the ongoing nature of investigations.

3. Credential Harvesting as the Real Goal

UNC6395 wasn’t just after corporate contacts. The focus on AWS keys and Snowflake tokens suggests a broader strategy: gaining persistent access to cloud infrastructures. This is not just about stealing data — it’s about building long-term footholds for deeper infiltration.

4. Third-Party Integrations: Weakest Link

Enterprises love SaaS because it boosts productivity, but integrations often trade security for convenience. The Drift case underlines how trusting third-party vendors without continuous monitoring can expose even the most security-focused companies like Zscaler.

5. Phishing Risks on the Horizon

Although the exposed Zscaler data seems limited (business contacts, licensing info), it’s highly valuable for targeted phishing. Threat actors can now craft convincing lures using legitimate details, increasing the risk of credential theft and fraud.

6. Industry-Wide Wake-Up Call

This breach is no longer about Zscaler, Salesloft, or Google. It’s about the fragility of SaaS trust chains. Security teams need to treat OAuth and API tokens as sensitive as passwords and rotate them regularly. Logs must be scrutinized, and redundant integrations should be cut off.

In essence, this is not just a breach—it’s a warning. The SaaS ecosystem is only as strong as its weakest app. Companies can no longer assume security is solely within their own infrastructure; they must extend zero-trust principles to every external integration.

🔍 Fact Checker Results

✅ Zscaler confirmed exposure of Salesforce data but no compromise of core infrastructure.
✅ Google and Mandiant verified OAuth tokens from Drift integrations were abused.
❌ Claims that only Salesforce users were impacted turned out false; Google Workspace was also affected.

📊 Prediction

The Salesloft Drift incident will not remain isolated. Expect:

More vendors acknowledging exposure in the coming weeks.

Regulatory bodies pressing SaaS firms to tighten OAuth security practices.
A push toward zero-trust SaaS integrations, where tokens and API connections are continuously verified instead of trusted indefinitely.
Threat actors reusing stolen credentials in follow-up phishing and cloud intrusion campaigns.

The next big cybersecurity crisis might not be a direct hack — but a silent chain reaction through the very SaaS tools enterprises depend on daily.

🕵️‍📝✔️Let’s dive deep and fact‑check.

References:

Reported By: securityaffairs.com
Extra Source Hub:
https://www.linkedin.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon