Sev0AI security incidents, tracked

All incidents / Supply chain and access

Stolen tokens from Drift's AI chat agent used to raid 700+ companies' Salesforce data

Salesloft (Drift), disclosed 20 Aug 2025. Supply chain and access Data exposed High

A threat actor used stolen OAuth tokens from the Drift AI chat agent's Salesforce integration to export data from hundreds of company Salesforce instances, hunting for AWS keys, passwords and other secrets. Victims included Cloudflare, Palo Alto Networks, Zscaler and Google. Salesloft and Salesforce revoked all Drift tokens.

Disclosed
20 Aug 2025
Organization
Salesloft (Drift)
Vendor
Unknown
Product
Drift
Type of AI
Chatbot
How it happened
Supply chain and access: Stolen token or key
Harm
Data exposed
Data involved
Credentials, Personal data, Internal documents
Reach
Many organizations
Records
700
Severity
High
Model at fault
No
Status
Confirmed

Sources

  1. https://www.finra.org/rules-guidance/guidance/salesloft-drift-AI-supply-chain-attack
  2. https://www.anomali.com/blog/salesloft-drift-breach-recap
  3. https://www.wtwco.com/en-us/insights/2025/09/the-drift-oauth-breach-a-cybersecurity-wake-up-call

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Stolen tokens from Drift's AI chat agent used to raid 700+ companies' Salesforce data", https://sev0.fyi/incidents/2025-08-20-salesloft-drift-oauth-theft/