When Trusted Apps Become Threat Vectors: Salesforce OAuth Breach Explained
Based on reporting from Cybersecurity Dive, August 21, 2025. In a newly disclosed campaign attributed to threat actor UNC6395, multiple Salesforce instances were breached through the compromise of OAuth tokens used by a third-party app, Drift. The attackers exploited these trusted tokens to harvest sensitive data from connected environmentsāincluding passwords, AWS keys, and Snowflake credentialsāwithout
Read More