What Happened?
The attack ran on two front simultaneously.
- On the first, attackers quietly compromised Salesloft's GitHub repositories between March and June 2025, stealing Drift OAuth refresh tokens. Those tokens gave them persistent, legitimate-looking API access to the Salesforce environments of every company using their integration. Thousands of database queries were run in the background, pulling contact records, case data, and critically embedded credentials like AWS keys and tokens that had been pasted into support tickets.
- On the second, attackers impersonated Salesforce support staff in targeted phone calls, tricking employees into installing a malicious app that granted OAuth access and bypassed MFA entirely. This campaign hit consumer brands directly.
Once they had accumulated enough data, the group went public. On 3 October 2025, they launched a dark web site called: Trinity of Chaos, published samples of...
>>[READ MORE]

What the Salesfoce breach can teach us on Cloud/SaaS Security?