Close Menu
The Washington FeedThe Washington Feed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chinese nationals jailed in South Africa over kidnapping and forced labour of Malawians

    September 10, 2025

    French police arrests 250 protesters as Macron installs a new PM

    September 10, 2025

    Trump Could Soon Strip Student Loan Forgiveness From Millions of Borrowers

    September 10, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    The Washington FeedThe Washington Feed
    Subscribe
    • Home
    • World
    • US
    • seattle
    • Politics
    • Business
    • Tech
    • Contact Us
    The Washington FeedThe Washington Feed
    Home»Tech»Salesloft says Drift customer data thefts linked to March GitHub account hack
    Tech

    Salesloft says Drift customer data thefts linked to March GitHub account hack

    adminBy adminSeptember 8, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Salesloft said a breach of its GitHub account in March allowed hackers to steal authentication tokens that were later used in a mass-hack targeting several of its big tech customers. 

    Citing an investigation by Google’s incident response unit Mandiant, Salesloft said on its data breach page that the as-yet-unnamed hackers accessed Salesloft’s GitHub account and performed reconnaissance activities from March until June, which allowed them to download “content from multiple repositories, add a guest user and establish workflows.” 

    The timeline raises fresh questions about the company’s security posture, including why it took Salesloft some six months to detect the intrusion.

    Salesloft said that the incident is now “contained.”

    Contact Us

    Do you have more information about these data breaches? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email. You also can contact TechCrunch via SecureDrop.

    After the hackers broke into its GitHub account, the company said the hackers accessed the Amazon Web Services cloud environment of Salesloft’s AI and chatbot-powered marketing platform Drift, which allowed them to steal OAuth tokens for Drift’s customers. OAuth is a standard that allows users to authorize one app or service to connect to another. By relying on OAuth, Drift can integrate with platforms like Salesforce and others to interact with website visitors. 

    In stealing these tokens, the threat actors breached several Salesloft’s customers, such as Bugcrowd, Cloudflare, Google, Proofpoint, Palo Alto Networks, and Tenable, among others, many of which are likely still unknown. 

    Google’s Threat Intelligence Group revealed the supply chain breach late in August, attributing it to a hacking group it calls UNC6395. 

    Techcrunch event

    San Francisco
    |
    October 27-29, 2025

    Cybersecurity publications DataBreaches.net and Bleeping Computer previously reported that the hackers behind the breach are the prolific hacking group known as ShinyHunters. The hackers are believed to be trying to extort victims by contacting them privately.

    By accessing Salesloft tokens, the hackers then access Salesforce instances, where they stole sensitive data contained in support tickets. “The actor’s primary objective was to steal credentials, specifically focusing on sensitive information like AWS access keys, passwords, and Snowflake-related access tokens,” Salesloft said on August 26.

    Salesloft said on Sunday that its integration with Salesforce is now restored.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    Jaguar Land Rover says data stolen in disruptive cyberattack

    September 10, 2025

    Ex-Google X trio wants their AI to be your second brain — and they just raised $6M to make it happen

    September 10, 2025

    Spotify is finally launching support for lossless music streaming

    September 10, 2025
    Leave A Reply Cancel Reply

    Demo
    Our Picks
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss

    Chinese nationals jailed in South Africa over kidnapping and forced labour of Malawians

    World September 10, 2025

    Seven Chinese nationals who smuggled Malawians to South Africa and subjected them to forced labour…

    French police arrests 250 protesters as Macron installs a new PM

    September 10, 2025

    Trump Could Soon Strip Student Loan Forgiveness From Millions of Borrowers

    September 10, 2025

    Man jumps off cruise ship allegedly to avoid $17K gambling debt in Puerto Rico

    September 10, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us

    At TheWashingtonFeed.com, we are committed to delivering accurate, timely, and relevant news from around the world. Whether it’s breaking developments in U.S. politics, major international affairs, or the latest trends in technology, our mission is to keep our readers informed with fact-driven journalism and insightful analysis.

    Email Us: Confordev@gmail.com

    Our Picks

    Chinese nationals jailed in South Africa over kidnapping and forced labour of Malawians

    September 10, 2025

    Jihadist groups executing civilians and burning homes, HRW warns

    September 10, 2025

    South Africa’s campaigners for healthy food

    September 10, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Contact Us
    • About Us
    • Privacy Policy
    • Terms and Condition
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.