Widespread Data Theft Targets Salesforce Instances via Salesloft Drift - Hunting pulse
Sept. 8, 2025, 11:33 a.m.
Description
A widespread data theft campaign, conducted by UNC6395, targeted Salesforce customer instances through compromised OAuth tokens associated with the Salesloft Drift application. The actor systematically exported large volumes of data from numerous corporate Salesforce instances, focusing on harvesting credentials and sensitive information. The campaign ran from August 8 to August 18, 2025, affecting various Salesforce objects such as Cases, Accounts, Users, and Opportunities. The actor demonstrated operational security awareness by deleting query jobs. Salesloft and Salesforce have taken measures to revoke access tokens and remove the Drift application from the Salesforce AppExchange. Impacted organizations are urged to take immediate remediation steps, including investigating for compromise, scanning for exposed secrets, and hardening access controls. The IPs provided are confirmed as malicious, but some may generate noise since they are associated with Tor exit nodes.
Tags
Date
- Created: Sept. 8, 2025, 10:16 a.m.
- Published: Sept. 8, 2025, 10:16 a.m.
- Modified: Sept. 8, 2025, 11:33 a.m.
Indicators
- 194.15.36.117
- 154.41.95.2
- 176.65.149.100
- 195.47.238.178
- 195.47.238.83
- 192.42.116.20
- 185.130.47.58
- 192.42.116.179