DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowFall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
Blog

Salesloft Drift Attackers Had GitHub Access Months Before Salesforce Campaign

By TheFinanceBase Team8 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Attackers accessed Salesloft’s GitHub environment between March and June 2025—months before using compromised Drift-related OAuth credentials to target customer Salesforce instances from August 8 through at least August 18. The timeline, detailed in Salesloft’s Mandiant investigation update, shows a supply-chain attack unfolding across source control, Drift, and customer integrations. It does not establish that every Salesloft system was continuously controlled throughout that period, or that Salesforce itself had a platform vulnerability.

What happened

The incident was not simply a breach of Salesforce. The documented chain began with access to Salesloft’s GitHub environment, continued through investigation of repositories and related systems, and later involved Drift-associated OAuth credentials used to reach customer Salesforce instances.

  1. GitHub access, March–June 2025: Mandiant’s investigation found that an actor accessed Salesloft’s GitHub account, downloaded content from multiple repositories, added a guest user, and established workflows.
  2. Reconnaissance and secret enumeration: The actor investigated Salesloft and Drift environments and enumerated secrets and environment variables. Repository access can expose more than source code: deployment settings, CI/CD workflows, cloud-resource references, integration details, and credentials may also be present.
  3. Drift credentials compromised: Investigators connected the activity to compromise of Drift-related OAuth credentials. The publicly described evidence does not show that every secret the actor encountered was valid or used.
  4. Customer Salesforce access, August 8–18: Google Threat Intelligence Group (GTIG) reported that the actor used compromised Drift credentials to access Salesforce customer environments, query data, and export it.

The clearest summary is that access to Salesloft’s GitHub environment preceded and helped enable a later campaign through trusted Drift integrations. The public account does not establish every causal step in detail, so it would be too strong to say GitHub alone was the initial access route for every part of the incident.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline: months between GitHub access and customer activity

Date What is known
March–June 2025 Mandiant’s investigation found access to Salesloft’s GitHub environment during this period, including repository downloads, a guest-user addition, and workflow activity. Salesloft Trust Center
August 8–18, 2025 GTIG observed the customer Salesforce campaign using compromised Drift-related OAuth credentials. Google Threat Intelligence Group
August 2025 Salesloft and Salesforce responded by revoking active Drift tokens and disabling or removing the integration while investigating. Salesforce said the Drift integration was disabled on August 28. Salesforce advisory
September 6, 2025 Salesloft published investigation findings that included the March–June GitHub access. Its Trust Center has continued to carry investigation updates.

These are distinct windows, not proof of six months of uninterrupted access. The established GitHub period is March through June; the customer-facing Salesforce activity began in August.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

How GitHub access could lead to Salesforce data

GitHub is an identity and infrastructure boundary as well as a place to store code. Repositories and their workflows can reveal how applications are deployed, what services they connect to, and where credentials or environment variables are used. If an attacker can read or influence relevant material, that can support reconnaissance and access to secrets. A secret found in a repository is not automatically usable, however, and finding it does not prove it was used.

In this incident, the later access path relied on OAuth credentials associated with Drift. OAuth lets an approved application act within the permissions granted to it. A stolen access or refresh token can therefore provide application-level access without looking like a conventional employee login. Employee MFA does not automatically protect an already-issued integration token.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Salesloft GitHub access (March–June 2025)
        ↓
Repository, workflow, and environment reconnaissance
        ↓
Drift-related credentials compromised
        ↓
OAuth access through trusted integrations
        ↓
Customer Salesforce queries and data exports (August 8–18)

GTIG tracks the actor as UNC6395. This is the tracking name to use for the campaign; claims connecting it to other named criminal groups should not be treated as settled attribution unless supported by a clearly attributed source.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the actor targeted in Salesforce

GTIG reported queries involving Salesforce objects including Account, Case, User, and Opportunity. It also described searches for additional credentials, including AWS access keys, passwords, and Snowflake-related tokens. The actor deleted query jobs, but GTIG said the underlying logs were not altered—an important reason to preserve and examine audit data rather than assuming that a missing job means no record remains.

Rank #3
Sale
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

Potential exposure varied by customer. It depended on whether Drift was connected, the OAuth scopes and Salesforce permissions granted, which objects and fields were accessible, and what information the organization stored in Salesforce. Sensitive information can reside in support cases, comments, attachments, custom fields, or metadata—not only in a designated password vault.

GTIG said Drift customers should treat tokens connected to the platform as potentially compromised, including tokens for integrations beyond Salesforce. Not using the Salesforce integration does not, by itself, demonstrate that an organization had no exposure through another Drift-connected service. Check the vendor’s incident guidance and your own integration inventory.

Rank #4
Thetis BIOFP Plus FIDO2 Fingerprint Security Key Hardware Passkey with USB Type C/Biometric/FIDO Certified, 2FA / MFA Authenticator App Device, Works for Window, macOS, Linux, Gmail, Github
  • FIDO2 Certified Passkey Authentication: Officially FIDO2 certified for secure, passwordless login on supported platforms. Use modern passkeys with hardware-backed protection. Please verify your intended service supports FIDO2 hardware keys before purchase.
  • Precision Fingerprint Sensor: Built-in high-accuracy biometric fingerprint sensor ensures fast, convenient authentication while preventing unauthorized access. No PIN reuse, no shared secrets—only your fingerprint unlocks the key.
  • Strong Hardware 2FA/MFA Security: Enhances account protection with physical-presence and biometric verification, helping defend against phishing, credential theft, and account takeovers.
  • USB-C Wired Compatibility (No NFC): Designed for stable USB-C authentication on desktops and laptops, including Windows, macOS, and Linux systems. Ideal for users and enterprises that prefer wired-only security keys.
  • Durable Aluminum Shield, Portable Design: Features the same precision aluminum protective shield for long-term durability. Compact, lightweight, battery-free, and network-free-built for everyday carry and professional environments.

What was compromised—and what is not established

  • Salesloft GitHub: Mandiant found access during March–June, repository downloads, a guest user, and workflows.
  • Drift and its credentials: The later campaign used compromised Drift-related OAuth credentials. The incident response included revoking active Drift access and refresh tokens.
  • Customer Salesforce instances: Some were accessed through trusted OAuth relationships, with queries and exports reported. Customer impact was not necessarily identical.
  • Salesforce’s platform: GTIG said the campaign was not caused by a vulnerability in Salesforce itself. “Salesforce was hacked” is therefore an imprecise shorthand for access to customer instances through a compromised integration.

The available evidence does not establish that every Salesloft system was compromised from March through August, that every Drift customer was affected in the same way, or that every exposed credential was used.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the timeline matters for detection

The gap between the documented GitHub access and the August customer activity raises practical questions about visibility across SaaS and development systems. It does not, on its own, prove which alerts fired or were missed. Security teams should assess whether their own controls would have surfaced:

Best Value
Sale
FIDO U2F Security Key, Thetis [Aluminum Folding Design] Universal Two Factor Authentication USB (Type A) for Extra Protection in Windows/Linux/Mac OS, Gmail, Facebook, Dropbox, SalesForce, GitHub
  • Protect Online Account - Offer a strong factor authentication to your online account. Never lose your accounts through password theft, phishing, hacking or keylogging scams.
  • Universal Compatibility - The Thetis U2F key can be used on any websites which support U2F protocol with the latest Chrome installed on your Windows, Mac OS or Linux. (Important Note: Not compatible with any email clients including Apple Mail, Mozilla Thunderbird or Microsoft Outlook)
  • FIDO-U2f-Certified - Safety is our priority. Certified by world's largest Ecosystem for Standards-based, interoperable Authentication. Only support U2F protocol (No UAF or OTP). Provide low-cost and simple solution with high security.
  • Extremly Durable - Designed with a 360° rotating metal cover that shields the USB connector when not in use. Also, crafted from a durable aluminum alloy to protect the Key from drops, bumps and scratches.
  • Portable Design - Compact, ultra-portable design allows you to take your FIDO key anywhere you need it.
  • Unusual personal access token creation or use, new GitHub Apps, or unexpected guest and outside-collaborator accounts.
  • Workflow creation or modification, changes to branch protection or deploy keys, repository downloads, or unexpected access to Actions secrets.
  • Cloud credentials used by CI/CD from unusual locations, identities, or times.
  • New OAuth grants, unexpected token use, unusual API volume, mass queries, or exports in Salesforce and other connected services.

GitHub’s secret-scanning documentation describes scanning for exposed credentials, including in Git history, and validity checks for detected secrets. Scanning helps find exposures; it does not by itself establish whether an attacker read a credential, whether it was active, whether it was used, or whether it has been revoked everywhere. Removing a value from the latest commit also does not erase it from history, clones, artifacts, or caches.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Response checklist for organizations

If Drift or a related integration was connected to your environment, treat this as an incident-response exercise, not merely a request to reset one application password. Preserve relevant logs first, coordinate with internal system owners, and use current vendor guidance to determine which connections and credentials require action.

Contain integrations and rotate credentials

  • Revoke Drift OAuth access and refresh tokens, and disconnect or disable Drift and Drift Email integrations as appropriate to your environment.
  • Do not reauthorize an integration until you have confirmed the vendor’s containment status and understand its required scopes.
  • Rotate credentials that may have been readable in repositories, workflow files, environment variables, deployment systems, or Salesforce records. Revoke existing sessions, grants, keys, and refresh tokens where the issuing service supports it.
  • Check connected services—including cloud platforms, data warehouses, identity systems, and other SaaS applications—for the same or related credentials.

Investigate GitHub and CI/CD

  • Review organization audit logs for personal access token creation and use, GitHub App installations, guest users and outside collaborators, repository downloads, and workflow changes.
  • Check Actions secrets access, deploy keys, branch-protection changes, suspicious commits, tags, releases, packages, and build artifacts.
  • Identify cloud roles and credentials available to workflows. Rotate exposed credentials at the provider and verify that replacements were not copied into the same exposed locations.
  • Preserve suspicious users, workflows, tokens, and artifacts as evidence before removing them, following your incident-response procedures.

Investigate Salesforce and other connected services

  • Review connected-app authorization history, OAuth use, login and API events, bulk exports, and unusual query activity.
  • Examine activity involving Account, Contact, Case, Opportunity, User, custom objects, and fields that might contain credentials or sensitive records.
  • Look for activity during August 8–18, 2025, including unusual IP or geographic patterns and deleted query jobs. Compare the period with your normal integration behavior.
  • Assess which records and secrets were accessible, then determine whether additional credential rotation, customer notification, regulatory reporting, or insurer notification is required under your obligations.
  • Review AWS, Snowflake, identity-provider, Salesforce, GitHub, and SIEM logs together. One console may show a token being used; another may show where its credential or workflow came from.

Longer-term controls: secure the whole relationship graph

The lesson is broader than “scan code for secrets.” A resilient program needs controls across identities, repositories, deployment workflows, cloud roles, OAuth grants, and SaaS audit logs.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Reduce repository and workflow exposure: Restrict guest access, review organization membership and GitHub Apps, protect workflow changes, and limit which secrets workflows can access.
  • Make secrets short-lived and revocable: Prefer narrowly scoped, short-lived credentials where supported. Maintain an inventory of where credentials are issued, stored, and used so a rotation reaches every dependent service.
  • Limit OAuth permissions: Grant integrations only the objects, fields, and actions they need. Reassess read versus write access, refresh-token needs, and whether a separate integration user can reduce the blast radius.
  • Monitor application identities: Alert on unexpected token issuance and use, abnormal API volume, unusual data exports, and access inconsistent with an integration’s normal purpose.
  • Centralize logs: Correlate GitHub audit events, identity-provider activity, cloud audit logs, Salesforce events, and connected-app activity in a SIEM or equivalent system. Keep retention long enough to investigate incidents that span months.

Secret scanning, cloud-security tooling, and SaaS security monitoring address different parts of this chain; none alone guarantees prevention. The useful security boundary is the relationship between systems and the identities and tokens that connect them.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.