Seriously Risky Business Newsletter
September 11, 2025
Exploiting Authorisation Sprawl Is the New Black
Presented by
Policy & Intelligence
The Salesloft Drift breach is a great example of the sprawling impact that a breach of a single service provider can have. Given that modern business models routinely involve software-as-a-service, these kinds of single-compromise-large-blast-radius attacks will become the new norm.
Salesloft's Drift application is an AI chatbot used by companies to convert website visitors into sales leads. Because it is typically integrated into Salesforce, its recent compromise has resulted in the theft of a large volume of Salesforce data from potentially hundreds of organisations. That stolen data also includes authentication tokens for various other services.
The breach began with the compromise of Salesloft's GitHub account in March. Over three months the threat actor conducted reconnaissance and downloaded content from multiple repositories. The actor, which Google is tracking as UNC6395, then moved to Drift's AWS environment and stole OAuth tokens for Drift's customers.