Google confirmed that attackers hijacked OAuth tokens from Salesloft’s Drift app to break into Salesforce databases, exposing customer credentials and sensitive data. The campaign, active between August 8–18, remains distinct from the ShinyHunters attacks on other major firms. Salesforce and Salesloft revoked tokens, pulled Drift from AppExchange, and urged affected customers to rotate credentials and audit for compromised secrets, including API keys and cloud service accounts.
