Salesforce Data Breach Shenanigans: The Drift Attack Comedy of Errors Unfolds!
Salesloft Drift app users beware! A sneaky supply chain attack has breached Salesforce data, targeting OAuth tokens and Google Workspace accounts. Hundreds are affected, with no vulnerabilities found in Salesforce or Google. Companies should review all third-party integrations, revoke credentials, and check for unauthorized access. Time to lock those digital doors!

Hot Take:
Looks like Salesforce customers got a not-so-friendly Drift into chaos! This supply chain attack is like that surprise party you never wanted – full of unexpected guests poking around in places they shouldn’t be. Pro tip: Always keep your tokens in check, or they might just drift away into the wrong hands!
Key Points:
- Supply chain attack targets Salesforce data via Salesloft Drift app.
- Google Workspace accounts also impacted, though in a limited scope.
- Organizations advised to treat all Drift authentication tokens as compromised.
- 183 new IP-based indicators of compromise (IoCs) discovered, linked to Tor exit nodes.
- The attack focused on exfiltrating credentials, affecting hundreds of organizations.
Already a member? Log in here