Stolen tokens from Drift's AI chat agent used to raid 700+ companies' Salesforce data
A threat actor used stolen OAuth tokens from the Drift AI chat agent's Salesforce integration to export data from hundreds of company Salesforce instances, hunting for AWS keys, passwords and other secrets. Victims included Cloudflare, Palo Alto Networks, Zscaler and Google. Salesloft and Salesforce revoked all Drift tokens.
- Disclosed
- 20 Aug 2025
- Organization
- Salesloft (Drift)
- Vendor
- Unknown
- Product
- Drift
- Type of AI
- Chatbot
- How it happened
- Supply chain and access: Stolen token or key
- Harm
- Data exposed
- Data involved
- Credentials, Personal data, Internal documents
- Reach
- Many organizations
- Records
- 700
- Severity
- High
- Model at fault
- No
- Status
- Confirmed