Salesloft Drift Supply Chain Attack Affects Hundreds of Businesses
Salesloft Drift插件漏洞导致客户数据泄露。攻击者于2025年3月至8月入侵Salesloft GitHub账户并窃取令牌访问Drift集成客户数据。Trustwave确认未受影响。Salesforce已修复集成。 2025-9-9 20:44:18 Author: www.trustwave.com(查看原文) 阅读量:5 收藏

Trustwave's Security & Compliance Team is aware of the Salesloft vulnerability affecting Drift chatbot integrations. Trustwave, A LevelBlue Company, and its affiliated entities do not utilize Drift, and Salesforce has confirmed the incident did not impact clients without this integration.

Based on current information, we confirm there has been no exposure or impact to us or our clients. As a trusted security partner, we’re on heightened alert for our clients and partners and are monitoring for any suspicious activity. Should new information arise that alters this assessment, we will provide an update directly.

For additional background on the vulnerability, Salesloft Drift, a third-party plugin for Salesforce to help automate contact and sales leads, was compromised between March and August 2025.

The Attack

The initial compromise began in March when the threat actor gained access through unknown means to the Salesloft GitHub account, downloading multiple private code repositories. The attacker maintained access through at least June. Leaked information allowed the threat actor to pivot to Drift's AWS environment in early August, leveraging that access to steal OAuth tokens for Drift integrations.

The threat actor then used the OAuth tokens to access Drift's customers' Salesforce integrations, allowing the download and exfiltration of this data. In an attempt to evade forensics, the threat actor also deleted the logged records of the queries and export jobs.

As of September 9, the integration between Salesloft and Salesforce has been restored.

Conclusion

These types of attacks cause massive damage with only a single compromise, because they target the supply chain of major organizations instead of attacking the organizations directly. By compromising just one organization, Salesloft Drift, the threat actors were able to pivot that access to compromise hundreds of organizations.

It's vital in this day and age to take an inventory of the third-party vendors your organization relies on and document the effect on your business if one of those suppliers is compromised. Finally, make sure that your suppliers are doing their due diligence to secure themselves.


文章来源: https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/salesloft-drift-supply-chain-attack-affects-hundreds-of-businesses/
如有侵权请联系:admin#unsafe.sh