Free tools Windows power users keep installed
One-click scans. No signup required.
Salesforce says it will “not engage, negotiate with, or pay any extortion demand” tied to the campaign involving Salesloft’s Drift application. The available reporting describes a compromise of Drift-related OAuth access that reached customer Salesforce environments—not evidence of a vulnerability in Salesforce’s core platform.
That distinction matters. A customer tenant could still have suffered unauthorized access or data theft, even if Salesforce infrastructure itself was not compromised. Organizations using Drift with Salesforce should investigate tokens, connected apps, API activity and exported data immediately.
What Salesforce confirmed
Salesforce’s position, reported by CRN, has three parts:
- It will not engage with the attackers.
- It will not negotiate over the extortion demand.
- It will not pay.
This is an extortion-response policy for the reported event. It does not eliminate the need for customer investigations, evidence preservation, legal review, notifications or remediation.
#1 Best Overall
Was Salesforce itself breached?
The cited reporting does not identify a compromise of Salesforce’s core platform. Salesforce told customers that the exposed information was associated with the earlier Salesloft Drift compromise and maintained that attackers did not obtain it by exploiting a Salesforce product flaw.
That does not mean no Salesforce data was accessed. Attackers could use a valid third-party OAuth path to operate inside individual customer tenants and extract records through Salesforce APIs. The precise description is therefore: customer Salesforce environments may have been accessed through a compromised integration, without evidence of a core Salesforce infrastructure breach.
How the Drift OAuth attack worked
Drift was the integration boundary
Salesloft’s Drift is a customer-engagement and chatbot application that can connect to Salesforce. OAuth lets an application act on an organization’s behalf after authorization.
A valid token can look legitimate
In the campaign tracked by Google Cloud and the FBI as UNC6395, attackers obtained or abused Drift-associated OAuth tokens. Those tokens could allow access without exploiting a Salesforce software vulnerability. Multifactor authentication remains important, but it does not automatically invalidate a token that has already been issued to an approved application.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Data moved through APIs
Google Cloud describes high-volume API activity and bulk exports from victim Salesforce tenants. Such activity may not be obvious in basic interactive-login records, making connected-app, API and export telemetry important to the investigation. Guidance is available from Google Cloud Threat Horizons.
Who may be affected?
Salesforce reportedly told customers that organizations without the Drift-Salesforce integration were outside the identified incident scope. That is a useful scoping indicator, not a guarantee that an organization has no Salesforce-related risk.
- Confirm whether Drift was connected to the Salesforce org during the relevant period.
- Inventory connected applications, OAuth scopes and integration users.
- Identify who authorized each application and when.
- Check whether tokens were active while suspicious API activity occurred.
- Review exports, bulk jobs, queries and downloads for abnormal volume.
Customers that never used Drift could still face separate Salesforce campaigns, including voice-phishing and malicious-connected-application activity associated with UNC6040.
What data may have been exposed?
CRN reported that affected information primarily included customer contact details and basic IT-support data, but could also include authorization tokens and IT-configuration information. The actual exposure depends on each tenant’s records, permissions and integration scope.
| Possible exposure | Why it matters |
|---|---|
| Customer, employee or partner records | Privacy, notification and targeted-phishing risk |
| Passwords, API keys or cloud credentials in fields or attachments | Downstream account takeover; reset outside Salesforce |
| OAuth tokens | Continued access until revoked or expired |
| IT configuration and support information | Better targeting for intrusion, fraud or social engineering |
A threat-controlled site reportedly claimed roughly 990 million records. That is an attacker allegation, not an independently verified breach total.
Which threat actors are linked to the activity?
UNC6395
Google Cloud and the FBI use UNC6395 for the campaign involving compromised Salesloft Drift OAuth tokens and Salesforce access. The FBI describes activity in August 2025. See the FBI cyber alert.
UNC6040
UNC6040 is a separate Salesforce-focused cluster associated with voice phishing and malicious connected applications, including fake or modified Data Loader applications. Its initial-access method should not be conflated with the Drift-token campaign.
ShinyHunters and other branding
The FBI says some UNC6040 victims received extortion emails allegedly sent under the ShinyHunters name. CRN described the group behind a Salesforce extortion site as involving ShinyHunters, Scattered Spider and Lapsus$, but those descriptions are reported characterizations rather than conclusive attribution. A leak-site name or ransom email alone does not prove who conducted every operation.
Recommended Free Tools
Rank #4
What “we won’t pay” means in practice
Refusing payment does not recover data already copied and does not end the incident. It means the company has chosen not to fund or negotiate with the extortion operation. Customers and responders still need to:
- Preserve logs, messages, samples and other evidence.
- Notify law enforcement, insurers, counsel and relevant regulators as appropriate.
- Determine whether data was merely accessed or actually exported.
- Revoke tokens and rotate exposed credentials.
- Prepare for publication, resale, phishing and follow-on fraud.
Salesforce’s policy is its stated position for this event, not a universal rule for every victim or jurisdiction. Each organization must consider its own legal, regulatory, contractual and safety obligations.
What Salesforce customers should do now
1. Contain the integration
- Identify Drift and every other Salesloft application connected to Salesforce.
- Revoke suspicious or unnecessary OAuth authorizations and disable noncritical integrations temporarily.
- Rotate Salesforce integration credentials and secrets that may have been stored in accessible records.
- Review connected-app permission scopes, integration users and ownership.
- Preserve relevant logs before making changes that could destroy evidence.
2. Investigate activity
Review Salesforce Login History, OAuth authorization events, Setup Audit Trail, API activity, Bulk API jobs, report exports, unusual query or queryMore activity, file and attachment downloads, permission changes, connected-app changes and sign-ins from unusual networks.
Google recommends telemetry covering Salesforce logins, configuration, connected applications, API use and exports. Some event types may require Salesforce Event Monitoring, Salesforce Shield or an Event Monitoring add-on; its hardening guidance explains the limitation.
3. Assess the data
- Map what each token and integration user could access during the token’s validity period.
- Search exposed records and attachments for passwords, API keys, cloud credentials and session tokens.
- Reset affected credentials in downstream systems, not only in Salesforce.
- Compare any attacker-provided samples with internal records without unnecessarily disclosing sensitive information.
4. Handle notification and monitoring
- Ask counsel and privacy teams whether customer, employee or regulator notifications are required.
- Engage an incident-response provider with Salesforce and SaaS-forensics experience when internal capability is limited.
- Watch for phishing and business-email-compromise attempts using CRM context.
- Continue monitoring for data publication, resale or renewed access.
Lessons for SaaS and integration security
- Trusted integrations are attack paths: vendor approval does not make every token or scope safe.
- OAuth tokens are credentials: govern their ownership, age, scope and revocation process.
- MFA is not the whole control: it does not by itself stop misuse of an already-authorized application.
- Normal-looking API traffic can hide theft: bulk exports and query volume require dedicated telemetry.
- CRM data can contain secrets: credentials and architecture details should not be stored casually in records or attachments.
- Third-party risk needs operational checks: review app permissions, token lifetimes, logging and data minimization—not only vendor questionnaires.
When security tooling may help
Organizations should first use controls they already own and confirm whether Salesforce Event Monitoring or Shield is enabled. A SIEM such as Splunk Enterprise Security, Microsoft Sentinel or Google Security Operations can correlate Salesforce events with identity and cloud telemetry, but licensing and ingestion costs vary.
Managed detection or incident-response services from providers such as Mandiant, CrowdStrike Services or Palo Alto Networks Unit 42 may be appropriate when token revocation, forensic analysis or regulatory assessment exceeds internal expertise. No product can retrieve data already exfiltrated or replace the containment steps above.
Timeline of the reported campaign
- Attackers compromised or abused OAuth credentials associated with Salesloft Drift.
- In August 2025, the FBI says UNC6395 used those tokens to access Salesforce environments.
- Attackers used Salesforce APIs and related access paths to export data.
- Stolen-data claims and extortion demands followed.
- Salesforce stated that it would not engage, negotiate or pay.
- CRN reported that an alleged leak site appeared to be taken down by the FBI; that report does not establish that the criminal operation or exposed data was fully resolved.
The Bottom Line
Salesforce’s refusal to pay addresses the extortion demand, not the underlying customer risk. The available evidence points to Salesloft Drift OAuth abuse reaching Salesforce tenants, so affected organizations must revoke access, investigate API and export activity, rotate downstream secrets and meet their own notification obligations.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




