Listen to this Post

🎯 Introduction
A new cybersecurity storm has erupted, shaking the trust in one of the world’s most widely used CRM systems. Google has revealed that a sophisticated hacking group, tracked as UNC6395, orchestrated widespread data theft by exploiting a third-party application integrated with Salesforce. The attacker’s weapon? Compromised OAuth tokens from an app called Salesloft Drift, a platform designed to automate and enhance sales processes using AI. This breach has exposed sensitive corporate data, including cloud credentials and system secrets, marking another alarming chapter in the ongoing battle against supply-chain attacks.
Massive Data Theft Through Salesforce: What Really Happened
Between August 8 and August 18, 2025, Google’s Threat Intelligence Group (GTIG) detected an aggressive campaign targeting Salesforce instances across multiple organizations. The attackers gained access through OAuth tokens—digital keys that allow apps to connect without sharing passwords. By compromising Salesloft Drift, which integrates deeply into Salesforce databases, UNC6395 was able to extract massive volumes of sensitive corporate data.
According to Google’s findings, the stolen data included Amazon Web Services (AWS) keys, passwords, and Snowflake access tokens. Once obtained, the hackers systematically combed through the data, searching for “secrets” that could be used to infiltrate or exploit additional systems. After their operation, they covered their digital tracks by deleting query jobs—a clever way to erase evidence of their activity.
While GTIG confirmed no direct tampering with log data, they advised all affected organizations to review system logs for signs of data exposure. The attacks were primarily limited to companies using Salesloft Drift integrated with Salesforce, meaning the risk was concentrated but severe.
Salesloft, Salesforce, and Google’s Swift Response
In a coordinated effort to contain the threat, Salesloft collaborated with Salesforce to revoke all active and refresh tokens associated with Drift. Salesforce also took a drastic but necessary step: removing Drift from the AppExchange until the full extent of the breach could be assessed.
Google emphasized that while Google Cloud customers were not directly impacted, any organization using Salesloft Drift should assume potential compromise and immediately inspect their Salesforce objects for exposed keys. The affected companies received direct notifications from GTIG, Salesforce, and Salesloft to initiate remediation.
This discovery follows a wave of earlier attacks involving high-profile brands such as Adidas, Pandora, Allianz, Tiffany & Co., Dior, Louis Vuitton, Workday, and even Google itself. In those incidents, a different group called ShinyHunters was responsible, primarily using vishing (voice phishing) to breach Salesforce systems.
Different Attack, Same Battlefield
Although the timeline of UNC6395’s campaign overlaps with earlier ShinyHunters incidents, Google made it clear that the Salesloft Drift operation was separate. “We’ve not seen any compelling evidence connecting them,” a GTIG spokesperson told Dark Reading.
Earlier, Google had warned about another financially motivated group, UNC6040, which masqueraded as IT support to gain Salesforce access through voice phishing. But the OAuth token theft linked to UNC6395 marks a different vector of attack—a deeper exploitation of trust within the app ecosystem.
Guidance for Defenders
Organizations impacted by this incident must act decisively. GTIG recommends:
Reviewing Salesforce objects for any sensitive information or credentials.
Revoking API keys and rotating compromised secrets.
Scanning for Indicators of Compromise (IOCs) using IPs and user-agent data shared by Google.
Checking Event Monitoring logs for suspicious activity related to the Drift connection user.
Configuring stricter access controls, limiting app permissions, and enforcing IP restrictions for all connected apps.
Google also urged defenders to rotate passwords, reset sessions, and implement timeout values to limit session exposure.
This event underscores the dangerous fragility of interconnected platforms. When one trusted app is compromised, entire ecosystems crumble.
What Undercode Say:
This breach is more than just another cyber incident—it’s a mirror reflecting the deeper weaknesses of modern cloud ecosystems. Organizations rely on third-party integrations to enhance productivity, but each connection introduces a new vulnerability chain. OAuth tokens, while convenient, are becoming one of the most targeted credentials in the threat landscape, precisely because they bypass traditional login barriers.
What makes this attack especially alarming is its precision. UNC6395 didn’t simply brute-force their way into Salesforce. They hijacked trust itself—the invisible handshake between platforms that was never designed to fail. Once inside, they didn’t destroy or disrupt systems. They harvested silently, extracting value while maintaining stealth. That level of operational discipline is the hallmark of an advanced, possibly state-backed or well-funded criminal group.
Salesloft’s Drift app, powered by AI-driven sales automation, ironically became the perfect entry point for exploitation. Its wide integration and access privileges turned it into a golden key for attackers. The larger message here is clear: as enterprise systems grow smarter, their attack surfaces expand exponentially.
Salesforce and Google acted quickly, but the damage goes beyond temporary token revocations. Trust between third-party apps and corporate systems has been shaken. Every organization using integrated SaaS platforms should now treat app permissions as high-risk assets, not routine configurations.
This also raises a philosophical question for the cybersecurity world: How secure can “zero-trust” architectures truly be when OAuth systems themselves are built on trust tokens? The industry’s challenge isn’t just to patch vulnerabilities—it’s to redefine digital trust for the era of automation and AI.
The breach further exposes how companies often underestimate supply-chain risk in SaaS environments. An exploited app can compromise multiple enterprises simultaneously, multiplying the fallout. And when brands like Dior, Louis Vuitton, and Google appear in breach reports, it sends a chilling signal: no one is too big to be exploited.
Going forward, we’ll likely see a surge in scrutiny of AppExchange and similar marketplaces, with Salesforce implementing more aggressive security checks. Expect mandatory token expiration policies, enhanced behavioral analytics for API usage, and AI-based anomaly detection to become the new norm.
The incident also spotlights a growing trend: the merging of financial motivation and espionage tactics. Groups like UNC6395 blur the line between cybercrime and cyberwarfare, leveraging stealth, automation, and cloud-native exploits to achieve persistent access.
isn’t just about a stolen token—it’s about a stolen layer of trust in the digital infrastructure of global business.
🔍 Fact Checker Results
✅ Verified: Google confirmed UNC6395’s role and OAuth exploitation through Salesloft Drift.
✅ Verified: Salesforce removed the Drift app from AppExchange pending investigation.
❌ No confirmed connection between UNC6395 and ShinyHunters/UNC6040 groups.
📊 Prediction
🔮 Expect stricter OAuth security standards across enterprise platforms.
🧠 AI-based token anomaly detection will become mainstream in SaaS security by 2026.
💥 Third-party integrations will face mandatory security audits before being approved in marketplaces like Salesforce AppExchange.
🕵️📝✔️Let’s dive deep and fact‑check.
References:
Reported By: www.darkreading.com
Extra Source Hub (Possible Sources for article):
https://www.medium.com
Wikipedia
OpenAi & Undercode AI
Image Source:
Unsplash
Undercode AI DI v2
Bing
🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]
📢 Follow UndercodeNews & Stay Tuned:
𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin | 🦋BlueSky | 🐘Mastodon




