The Abyss of the Salesloft-Salesforce Breach May Reach the Challenger Deep
- By Forrester analysts
- September 15, 2025

News has been trickling out since August 20 about a security issue in Salesloft’s Drift product, a marketing and sales chatbot that integrates with CRM systems to capture and track sales opportunities. The issue started in March, when threat actors accessed Salesloft’s GitHub account and did reconnaissance, which helped them access Drift’s AWS environment and obtain OAuth tokens. From there, they accessed Drift customers’ Salesforce instances from August 8–18.
Salesforce has suffered repeated attacks this year where advanced persistent threats (APTs) compromised customer databases by targeting individual companies. This attack is much broader in terms of both scope and number of companies affected, as Drift is a popular tool used by over 700 companies. Its customers include several notable cybersecurity vendors such as Black Duck, Cloudflare, Okta, OneTrust, Palo Alto Networks, Proofpoint, and Zscaler.
What data was compromised?
By design, Drift is meant to improve sales engagement with prospects and customers. Its integration with CRM systems lets Drift track leads, update CRM records, and trigger follow-up actions. Because of the Salesforce integration, the threat actors were able to access:
- Sensitive information about client environments, such as IP addresses, account information, and access tokens. These are stored in clear text within support case notes to make supporting that customer easier when a case is passed to multiple analysts, but for a hacker, this gives them critical access details to the client’s infrastructure.
- Standard information about accounts, such as client contact data, sales pipeline, support history, and business strategy. This information seems generic, but for social engineering campaigns, these are the details that threat actors need to make their engagement more believable.
Actions to take now to reduce the threat to your business
While Salesloft has reset the authentication tokens and temporarily disabled Drift, impacted businesses need to take further steps to protect themselves and their employees. After working with their third-party risk management program to define the scope of the breach, companies should take the following actions:
- Revoke and rotate all API keys, credentials, and authentication tokens associated with the integration. Additionally, if your investigation of your Salesforce data uncovers any hardcoded secrets or exposed API keys/credentials, they must be rotated immediately. Establish a regular rotation schedule for all API keys and other secrets used in third-party integrations to reduce the window of exposure.
- Tune tech and train teams for the social engineering onslaught. Various human-element breach types and tactics will spring up in the coming weeks and months based on the data that was extracted, requiring specific tech and process controls. Your email, messaging, and collaboration security solution and your employees should be tuned to spot the traditional signs of social engineering: authority, novelty, and urgency. Employees should be encouraged — and publicly praised — to pause in the face of these signs and seek additional verification before providing information or completing transactions.
- Institute least privileged access controls on your data used by third parties. The guidance we’ve provided on SaaS security applies equally to app developers and customers to limit access to data to only what is needed for that function to execute. In this campaign, companies that restricted inbound access from approved IP addresses did not have their Salesforce data extracted, even though they were targeted. Utilize SaaS security posture management solutions to uncover the risks in your SaaS deployments and improve threat monitoring of your configurations within these apps to limit your exposure based on identified risks.
- Secure your software supply chain. Start with an inventory of all software used in the development and delivery process; this includes open-source software tools and components. Ensure that dev environments, pipelines, and source-code management systems utilize Zero Trust principles, have phishing-resistant multifactor authentication enforced, enable branch protection, monitor for security misconfigurations, automate application security testing, and utilize a secrets management solution to avoid any credentials, tokens, or environment variables being passed in plaintext.
- Define your incident escalation matrix. Delineate severity levels and assess materiality in the context of the regulatory requirements to which your organization is beholden. Socialize this matrix with all internal and external stakeholders, and work with outside counsel and your incident response service provider to develop executive and board tabletop exercises involving complex, cascading nth-party breach and breach notification scenarios.
Stay tuned
Details continue to emerge from Salesloft as well as businesses directly impacted by the breach. Because we still don’t know how many companies were victims of data theft or the exact attack details, the total impact remains unclear.
The original article is here.
The views and opinions expressed in this article are those of the author and do not necessarily reflect those of CDOTrends. Image credit: iStockphoto/francescoch
Forrester analysts
Paddy Harrington is Forrester’s senior analyst. He focuses on endpoint security across a range of platforms, including desktop PCs, internet-of-things (IoT) devices, connected vehicles, and operational technology (OT). His research includes the endpoint’s impact on the security of business data and operations in light of the proliferation of interconnected devices and the evolving work environment.
Geoff Cairns is Forrester’s principal analyst. His research focuses on workforce IAM, including topics such as multifactor authentication (MFA), privileged identity management, identity governance and lifecycle, and identity as a service (IDaaS). He guides clients on IAM technologies and services, as well as associated integrations and operational processes to address the business and security needs of the evolving workforce environment.
Jeff Pollard is Forrester’s vice president and principal analyst. He leads Forrester’s research on the role of the CISO, specializing in topics related to security strategy, budgets, metrics, business cases, and presenting to the board. His research also includes security services, featuring global coverage of managed security services, professional security services, and security-as-a-service.
Jess Burn is Forrester’s principal analyst. She contributes to Forrester’s research on the role of the CISO with a focus on security talent management. Additionally, Jess covers incident response and crisis management, and email security.
Janet Worthington is Forrester’s senior analyst. She covers product security, proactive security design, securing new development methods, security testing in the software delivery lifecycle, and collaboration between security, development, and product management.
Heidi Shey is Forrester’s principal analyst. She guides security leaders and tech executives at enterprise and government organizations in applying a Zero Trust, data-centric approach to securing data. She advises in areas such as sensitive data discovery and classification, data loss prevention, data security platforms, secure communications solutions, privacy preserving technologies, other data-centric security controls, and post-quantum security.
Stephanie Liu is Forrester’s senior analyst. She focuses on the intersection of marketing and privacy. She guides clients on how to strike a delicate balance between privacy, trust, and consumer expectations, all while navigating a rapidly shifting data deprecation landscape that spans consumers’ privacy-protecting behaviors, regulation, tech limitations, and walled gardens.
Jitin Shabadu is a Forrester analyst.