Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Salesforce Won’t Engage, Negotiate With or Pay Threat Actors After Salesloft Drift Data Theft

Salesforce says it will not engage, negotiate with or pay attackers linked to a Salesloft Drift OAuth campaign. Here is what customers should investigate, revoke and reset.
From TheFinanceBase Team6 min to read

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Salesforce says it will “not engage, negotiate with, or pay any extortion demand” tied to the campaign involving Salesloft’s Drift application. The available reporting describes a compromise of Drift-related OAuth access that reached customer Salesforce environments—not evidence of a vulnerability in Salesforce’s core platform.

That distinction matters. A customer tenant could still have suffered unauthorized access or data theft, even if Salesforce infrastructure itself was not compromised. Organizations using Drift with Salesforce should investigate tokens, connected apps, API activity and exported data immediately.

What Salesforce confirmed

Salesforce’s position, reported by CRN, has three parts:

  • It will not engage with the attackers.
  • It will not negotiate over the extortion demand.
  • It will not pay.

This is an extortion-response policy for the reported event. It does not eliminate the need for customer investigations, evidence preservation, legal review, notifications or remediation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Was Salesforce itself breached?

The cited reporting does not identify a compromise of Salesforce’s core platform. Salesforce told customers that the exposed information was associated with the earlier Salesloft Drift compromise and maintained that attackers did not obtain it by exploiting a Salesforce product flaw.

That does not mean no Salesforce data was accessed. Attackers could use a valid third-party OAuth path to operate inside individual customer tenants and extract records through Salesforce APIs. The precise description is therefore: customer Salesforce environments may have been accessed through a compromised integration, without evidence of a core Salesforce infrastructure breach.

How the Drift OAuth attack worked

Drift was the integration boundary

Salesloft’s Drift is a customer-engagement and chatbot application that can connect to Salesforce. OAuth lets an application act on an organization’s behalf after authorization.

A valid token can look legitimate

In the campaign tracked by Google Cloud and the FBI as UNC6395, attackers obtained or abused Drift-associated OAuth tokens. Those tokens could allow access without exploiting a Salesforce software vulnerability. Multifactor authentication remains important, but it does not automatically invalidate a token that has already been issued to an approved application.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Data moved through APIs

Google Cloud describes high-volume API activity and bulk exports from victim Salesforce tenants. Such activity may not be obvious in basic interactive-login records, making connected-app, API and export telemetry important to the investigation. Guidance is available from Google Cloud Threat Horizons.

Who may be affected?

Salesforce reportedly told customers that organizations without the Drift-Salesforce integration were outside the identified incident scope. That is a useful scoping indicator, not a guarantee that an organization has no Salesforce-related risk.

  • Confirm whether Drift was connected to the Salesforce org during the relevant period.
  • Inventory connected applications, OAuth scopes and integration users.
  • Identify who authorized each application and when.
  • Check whether tokens were active while suspicious API activity occurred.
  • Review exports, bulk jobs, queries and downloads for abnormal volume.

Customers that never used Drift could still face separate Salesforce campaigns, including voice-phishing and malicious-connected-application activity associated with UNC6040.

What data may have been exposed?

CRN reported that affected information primarily included customer contact details and basic IT-support data, but could also include authorization tokens and IT-configuration information. The actual exposure depends on each tenant’s records, permissions and integration scope.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Possible exposure Why it matters
Customer, employee or partner records Privacy, notification and targeted-phishing risk
Passwords, API keys or cloud credentials in fields or attachments Downstream account takeover; reset outside Salesforce
OAuth tokens Continued access until revoked or expired
IT configuration and support information Better targeting for intrusion, fraud or social engineering

A threat-controlled site reportedly claimed roughly 990 million records. That is an attacker allegation, not an independently verified breach total.

Which threat actors are linked to the activity?

UNC6395

Google Cloud and the FBI use UNC6395 for the campaign involving compromised Salesloft Drift OAuth tokens and Salesforce access. The FBI describes activity in August 2025. See the FBI cyber alert.

UNC6040

UNC6040 is a separate Salesforce-focused cluster associated with voice phishing and malicious connected applications, including fake or modified Data Loader applications. Its initial-access method should not be conflated with the Drift-token campaign.

ShinyHunters and other branding

The FBI says some UNC6040 victims received extortion emails allegedly sent under the ShinyHunters name. CRN described the group behind a Salesforce extortion site as involving ShinyHunters, Scattered Spider and Lapsus$, but those descriptions are reported characterizations rather than conclusive attribution. A leak-site name or ransom email alone does not prove who conducted every operation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What “we won’t pay” means in practice

Refusing payment does not recover data already copied and does not end the incident. It means the company has chosen not to fund or negotiate with the extortion operation. Customers and responders still need to:

  • Preserve logs, messages, samples and other evidence.
  • Notify law enforcement, insurers, counsel and relevant regulators as appropriate.
  • Determine whether data was merely accessed or actually exported.
  • Revoke tokens and rotate exposed credentials.
  • Prepare for publication, resale, phishing and follow-on fraud.

Salesforce’s policy is its stated position for this event, not a universal rule for every victim or jurisdiction. Each organization must consider its own legal, regulatory, contractual and safety obligations.

What Salesforce customers should do now

1. Contain the integration

  1. Identify Drift and every other Salesloft application connected to Salesforce.
  2. Revoke suspicious or unnecessary OAuth authorizations and disable noncritical integrations temporarily.
  3. Rotate Salesforce integration credentials and secrets that may have been stored in accessible records.
  4. Review connected-app permission scopes, integration users and ownership.
  5. Preserve relevant logs before making changes that could destroy evidence.

2. Investigate activity

Review Salesforce Login History, OAuth authorization events, Setup Audit Trail, API activity, Bulk API jobs, report exports, unusual query or queryMore activity, file and attachment downloads, permission changes, connected-app changes and sign-ins from unusual networks.

Google recommends telemetry covering Salesforce logins, configuration, connected applications, API use and exports. Some event types may require Salesforce Event Monitoring, Salesforce Shield or an Event Monitoring add-on; its hardening guidance explains the limitation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Assess the data

  1. Map what each token and integration user could access during the token’s validity period.
  2. Search exposed records and attachments for passwords, API keys, cloud credentials and session tokens.
  3. Reset affected credentials in downstream systems, not only in Salesforce.
  4. Compare any attacker-provided samples with internal records without unnecessarily disclosing sensitive information.

4. Handle notification and monitoring

  • Ask counsel and privacy teams whether customer, employee or regulator notifications are required.
  • Engage an incident-response provider with Salesforce and SaaS-forensics experience when internal capability is limited.
  • Watch for phishing and business-email-compromise attempts using CRM context.
  • Continue monitoring for data publication, resale or renewed access.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Lessons for SaaS and integration security

  • Trusted integrations are attack paths: vendor approval does not make every token or scope safe.
  • OAuth tokens are credentials: govern their ownership, age, scope and revocation process.
  • MFA is not the whole control: it does not by itself stop misuse of an already-authorized application.
  • Normal-looking API traffic can hide theft: bulk exports and query volume require dedicated telemetry.
  • CRM data can contain secrets: credentials and architecture details should not be stored casually in records or attachments.
  • Third-party risk needs operational checks: review app permissions, token lifetimes, logging and data minimization—not only vendor questionnaires.

When security tooling may help

Organizations should first use controls they already own and confirm whether Salesforce Event Monitoring or Shield is enabled. A SIEM such as Splunk Enterprise Security, Microsoft Sentinel or Google Security Operations can correlate Salesforce events with identity and cloud telemetry, but licensing and ingestion costs vary.

Managed detection or incident-response services from providers such as Mandiant, CrowdStrike Services or Palo Alto Networks Unit 42 may be appropriate when token revocation, forensic analysis or regulatory assessment exceeds internal expertise. No product can retrieve data already exfiltrated or replace the containment steps above.

Timeline of the reported campaign

  1. Attackers compromised or abused OAuth credentials associated with Salesloft Drift.
  2. In August 2025, the FBI says UNC6395 used those tokens to access Salesforce environments.
  3. Attackers used Salesforce APIs and related access paths to export data.
  4. Stolen-data claims and extortion demands followed.
  5. Salesforce stated that it would not engage, negotiate or pay.
  6. CRN reported that an alleged leak site appeared to be taken down by the FBI; that report does not establish that the criminal operation or exposed data was fully resolved.

The Bottom Line

Salesforce’s refusal to pay addresses the extortion demand, not the underlying customer risk. The available evidence points to Salesloft Drift OAuth abuse reaching Salesforce tenants, so affected organizations must revoke access, investigate API and export activity, rotate downstream secrets and meet their own notification obligations.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.