Data Breaches

Hundreds of Salesforce Customers Hit by Widespread Data Theft Campaign

Google says the hackers systematically exported corporate data, focusing on secrets such as AWS and Snowflake keys.

Salesforce data theft extortion

Hackers stole data from hundreds of Salesforce customer instances in a widespread campaign earlier this month, Google Threat Intelligence Group (GTIG) warns.

The attacks did not exploit a vulnerability within the core Salesforce platform, but relied on compromised OAuth tokens for Salesloft Drift, a third-party AI chat bot.

The campaign, GTIG says, was carried out by a threat actor tracked as UNC6395 between August 8 and August 18, 2025.

“The actor systematically exported large volumes of data from numerous corporate Salesforce instances. GTIG assesses the primary intent of the threat actor is to harvest credentials,” Google’s threat intelligence unit says.

UNC6395 was seen searching the stolen information for secrets and sensitive information, including AWS access keys, passwords, and Snowflake-related access tokens.

“The threat actor used a python tool to automate the data theft process for each organization that was targeted,” GTIG principal threat analyst Austin Larsen told SecurityWeek.

Advertisement. Scroll to continue reading.

Salesloft, which shared indicators of compromise (IOCs) to help customers identify potential compromises, has pointed out that only organizations integrating Drift with Salesforce have been affected by the incident.

Working with Salesforce, Salesloft revoked the tokens for Drift on August 20. Thus, all Drift-Salesforce connections need to be re-authenticated to re-enable the integration.

“We have determined that this incident did not impact customers who do not use our Drift-Salesforce integration. Based on our ongoing investigation, we do not see evidence of ongoing malicious activity related to this incident,” Salesloft said on Tuesday.

According to GTIG, hundreds of organizations were compromised in these attacks, but Salesforce, which has removed Drift from AppExchange, says the hackers only accessed a small number of customer instances via the Drift connection to the platform and that all the affected customers were notified.

Organizations integrating Drift with Salesforce should consider their Salesforce data compromised, GTIG says, advising them to hunt for signs of compromise and rotate all credentials and secrets contained within Salesforce objects.

“UNC6395 demonstrated operational security awareness by deleting query jobs, however logs were not impacted and organizations should still review relevant logs for evidence of data exposure,” GTIG notes.

*Updated with additional information from GTIG.

Related: Docker Desktop Vulnerability Leads to Host Compromise

Related: Chinese Silk Typhoon Hackers Targeting Multiple Industries in North America

Related: AWS Trusted Advisor Tricked Into Showing Unprotected S3 Buckets as Secure

Related:Australia’s TPG Telecom Investigating iiNet Hack

Related Content

Data Breaches

The hackers claimed to have stolen more than 600,000 Salesforce records, including personal information and corporate data. 

Cybercrime

Salesforce has confirmed that customers are being targeted via poorly secured instances.

Data Breaches

Luxury brands were among the dozens of major companies whose Salesforce instances were targeted by Scattered LAPSUS$ Hunters.

Data Breaches

The infamous ShinyHunters hackers have targeted customer-managed Gainsight-published applications to steal data from Salesforce instances.

Data Breaches

Salesforce says the extortion attempts are related to past or unsubstantiated incidents, and not to fresh intrusions.

Data Breaches

The company says customer contact information was stolen from a third-party service provider’s platform.

Malware & Threats

The cybercrime groups tracked as UNC6040 and UNC6395 have been extorting organizations after stealing data from their Salesforce instances.

Data Breaches

The list of impacted cybersecurity firms has been expanded to include BeyondTrust, Bugcrowd, CyberArk, Cato Networks, JFrog, and Rubrik.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version