Salesloft says Drift customer data thefts linked to March GitHub account hack

<span class="caption">Hand working at laptop computer illustrating cyber crime | Image Credits:Andrew Brookes</span>
Hand working at laptop computer illustrating cyber crime | Image Credits:Andrew Brookes

Salesloft said a breach of its GitHub account in March allowed hackers to steal authentication tokens that were later used in a mass-hack targeting several of its big tech customers.

Citing an investigation by Google’s incident response unit Mandiant, Salesloft said on its data breach page that the as-yet-unnamed hackers accessed Salesloft’s GitHub account and performed reconnaissance activities from March until June, which allowed them to download “content from multiple repositories, add a guest user and establish workflows.”

The timeline raises fresh questions about the company’s security posture, including why it took Salesloft some six months to detect the intrusion.

Salesloft said that the incident is now “contained.”

Do you have more information about these data breaches? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

After the hackers broke into its GitHub account, the company said the hackers accessed the Amazon Web Services cloud environment of Salesloft’s AI and chatbot-powered marketing platform Drift, which allowed them to steal OAuth tokens for Drift’s customers. OAuth is a standard that allows users to authorize one app or service to connect to another. By relying on OAuth, Drift can integrate with platforms like Salesforce and others to interact with website visitors.

In stealing these tokens, the threat actors breached several Salesloft’s customers, such as Bugcrowd, Cloudflare, Google, Proofpoint, Palo Alto Networks, and Tenable, among others, many of which are likely still unknown.

Google’s Threat Intelligence Group revealed the supply chain breach late in August, attributing it to a hacking group it calls UNC6395.

Cybersecurity publications DataBreaches.net and Bleeping Computer previously reported that the hackers behind the breach are the prolific hacking group known as ShinyHunters. The hackers are believed to be trying to extort victims by contacting them privately.

By accessing Salesloft tokens, the hackers then access Salesforce instances, where they stole sensitive data contained in support tickets. “The actor’s primary objective was to steal credentials, specifically focusing on sensitive information like AWS access keys, passwords, and Snowflake-related access tokens,” Salesloft said on August 26.

Salesloft said on Sunday that its integration with Salesforce is now restored.

Source link

Advertisement

spot_img

Wayfair (W) Soars 20%...

We recently published 10 Big Names...

Nifty Prediction Today –...

Nifty 50 opened today’s session with a gap-up...

How Y2K Teen Brands...

Gen-Z’s Y2K obsession is still going strong —...

Wayfair (W) Soars 20%...

We recently published 10 Big Names...

Wayfair (W) Soars 20% as Firm Posts Bullish Outlook

We recently published 10 Big Names With Double-Digit Upsides. Wayfair Inc. (NYSE:W) is one of last week’s top performers. ...

Nifty Prediction Today – September 9, 2025: Nifty futures: Facing a barrier

Nifty 50 opened today’s session with a gap-up at 24,864 versus yesterday’s close of 24,773. It is currently hovering around 24,850, up 0.3...

How Y2K Teen Brands Are Winning in the TikTok Era

Gen-Z’s Y2K obsession is still going strong — and no one is benefitting more than the retailers that dressed teens 20 years ago....

Wayfair (W) Soars 20% as Firm Posts Bullish Outlook

We recently published 10 Big Names With Double-Digit Upsides. Wayfair Inc. (NYSE:W) is one of last week’s top performers. ...

Oscar Health (OSCR) Surges 16.6% as Firm Reaffirms 2025 Growth Guidance

We recently published 10 Big Names With Double-Digit Upsides. Oscar Health, Inc. (NYSE:OSCR) is one of last week’s top performers....

US Property Insurance Costs Hit New High as Disasters Worsen

The cost of property insurance in the US rose to an all time-high in the...

I Love C3.ai, Inc. (AI)’s CEO, Says Jim Cramer On Recent 7% Share Price Drop

We recently published 11 Stocks Jim Cramer Discussed As He Said Apple’s CEO Is A “Pawn”. C3.ai, Inc. (NYSE:AI) is...