Salesloft Drift Supply Chain Attack Affects Hundreds of Businesses
Salesloft漏洞影响Drift聊天机器人集成,导致数据泄露风险。攻击者通过入侵Salesloft GitHub获取代码库,并利用其访问Drift AWS环境及OAuth令牌。此漏洞使威胁行为者能够访问客户的 Salesforce 数据并删除相关日志记录。Trustwave确认未受影响,并强调第三方供应商安全的重要性以防范此类供应链攻击风险。 2025-9-9 20:44:18 Author: levelblue.com(查看原文) 阅读量:0 收藏

Trustwave's Security & Compliance Team is aware of the Salesloft vulnerability affecting Drift chatbot integrations. Trustwave, A LevelBlue Company, and its affiliated entities do not utilize Drift, and Salesforce has confirmed the incident did not impact clients without this integration.

Based on current information, we confirm there has been no exposure or impact to us or our clients. As a trusted security partner, we’re on heightened alert for our clients and partners and are monitoring for any suspicious activity. Should new information arise that alters this assessment, we will provide an update directly.

For additional background on the vulnerability, Salesloft Drift, a third-party plugin for Salesforce to help automate contact and sales leads, was compromised between March and August 2025.

The Attack

The initial compromise began in March when the threat actor gained access through unknown means to the Salesloft GitHub account, downloading multiple private code repositories. The attacker maintained access through at least June. Leaked information allowed the threat actor to pivot to Drift's AWS environment in early August, leveraging that access to steal OAuth tokens for Drift integrations.

The threat actor then used the OAuth tokens to access Drift's customers' Salesforce integrations, allowing the download and exfiltration of this data. In an attempt to evade forensics, the threat actor also deleted the logged records of the queries and export jobs.

As of September 9, the integration between Salesloft and Salesforce has been restored.

Conclusion

These types of attacks cause massive damage with only a single compromise, because they target the supply chain of major organizations instead of attacking the organizations directly. By compromising just one organization, Salesloft Drift, the threat actors were able to pivot that access to compromise hundreds of organizations.

It's vital in this day and age to take an inventory of the third-party vendors your organization relies on and document the effect on your business if one of those suppliers is compromised. Finally, make sure that your suppliers are doing their due diligence to secure themselves.


文章来源: https://levelblue.com/en-us/resources/blogs/spiderlabs-blog/salesloft-drift-supply-chain-attack-affects-hundreds-of-businesses/
如有侵权请联系:admin#unsafe.sh