CSIDB logo
Incident

Salesforce

Incident posture

Attack window
2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:33

Linked entities

Victim
Salesforce
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A large-scale data breach exploited compromised OAuth tokens to gain access to hundreds of Salesforce customer environments, exposing millions of records containing contact details and account information. Listed among the most significant cyber incidents of the year by Tokio Marine HCC International's annual cyber incidents report, the breach underscored the systemic risk posed by technology supply-chain and third-party integration vulnerabilities. The incident was selected for its operational disruption, broad implications across the digital ecosystem, and the scale of customer data exposed, highlighting how interconnected SaaS platforms can amplify the reach of a single compromise.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

The Salesforce / Drift OAuth large-scale data breach emerged as one of the most significant cyber incidents of 2025, according to the sixth consecutive annual cyber incidents report published by Tokio Marine HCC International (TMHCCI). The incident, which exploited compromised OAuth tokens associated with the Drift integration, allowed threat actors to gain unauthorized access to hundreds of Salesforce customer environments. Once inside these environments, the attackers were able to exfiltrate records, contact details, and account information belonging to millions of customers across multiple organizations that relied on the Salesforce platform. The breach highlighted the systemic risks that arise when third-party integrations and authentication mechanisms become vectors for large-scale data exposure, particularly in environments where sensitive customer data is centrally stored.

The mechanism of the attack centered on OAuth token abuse, a technique that takes advantage of legitimate authentication credentials to bypass traditional security controls. OAuth tokens are typically used to enable seamless communication between connected applications, such as the Drift conversational marketing platform and Salesforce customer relationship management environments. When these tokens were compromised, attackers could impersonate authorized integrations and move laterally into customer Salesforce instances without triggering immediate alerts. This approach allowed the threat actors to operate within trusted boundaries, extracting data at scale from hundreds of separate customer environments. The breadth of the impact, affecting hundreds of organizations simultaneously, underscored how a single compromised integration can cascade into a multi-tenant data exposure event spanning multiple industries and geographies.

The scope of the breach was substantial, with reports indicating that millions of customer records were exposed across the affected Salesforce environments. The compromised data included contact details and account information, categories of information that are highly valuable for subsequent phishing campaigns, identity theft, and social engineering attacks. Because Salesforce serves as a central repository for customer relationship data across many enterprises, the breach had downstream implications for the security posture of every organization whose environment was accessed. Each affected organization faced its own notification obligations, regulatory scrutiny, and reputational considerations, amplifying the overall impact of the incident beyond the initial point of compromise.

While specific details regarding the timeline of detection, the identity of the threat actors, and the exact sequence of containment actions were not disclosed in the TMHCCI report, the incident was significant enough to be included among the ten most notable cyber events of 2025. Its selection alongside incidents affecting Marks & Spencer, Jaguar Land Rover, Amazon Web Services, and other major organizations reflects the report's emphasis on events that demonstrate operational disruption, financial impact, and broader implications for the global digital ecosystem. The Salesforce / Drift breach was particularly noteworthy for illustrating the dangers of supply-chain and integration-based attacks, a category of threat that continues to challenge organizations that depend on interconnected software platforms.

The incident also drew attention to the broader trend of cloud infrastructure concentration and the risks inherent in relying on widely adopted SaaS platforms. As organizations increasingly integrate third-party tools with core business systems, the attack surface expands to include the security posture of every connected vendor and integration. The exploitation of OAuth tokens in the Salesforce / Drift breach demonstrated how a vulnerability in one component of an integrated ecosystem can be leveraged to compromise hundreds of downstream environments. This pattern of risk multiplication is a defining characteristic of modern supply-chain attacks and was a recurring theme throughout the 2025 cyber incidents documented by TMHCCI.

The report's authors, including Isaac Guasch, cyber security leader and author of the report, noted that tracking such incidents year-over-year helps the insurance market and broader cybersecurity community understand emerging threats. The inclusion of the Salesforce / Drift breach in the top ten list signals recognition within the cyber underwriting community that integration-layer compromises represent a material and evolving risk. Xavier Marguinaud, head of Cyber at Tokio Marine HCC International, emphasized that the past year marked a turning point as artificial intelligence evolved from a theoretical risk to an active threat, though the Salesforce / Drift breach itself was attributed to OAuth token exploitation rather than AI-driven techniques. The incident nonetheless reinforced the report's broader message about the increasing sophistication and scale of cyber threats facing organizations worldwide.

The financial and operational consequences of the breach, while not quantified in specific figures within the TMHCCI report, were nonetheless significant given the scale of customer data exposure. Organizations affected by the breach faced costs associated with incident response, forensic investigation, customer notification, regulatory compliance, and potential litigation. The reputational impact on both Salesforce and Drift, as well as on the hundreds of customer organizations whose data was accessed, contributed to heightened scrutiny of third-party integration security practices across the industry. The incident served as a catalyst for renewed focus on token management, integration monitoring, and the principle of least privilege in SaaS environments.

In the broader context of the 2025 cyber threat landscape, the Salesforce / Drift OAuth breach stood out as a demonstration of how attackers continue to find leverage in the connective tissue between enterprise applications. The ability to compromise hundreds of customer environments through a single integration vulnerability illustrated the systemic risks of interconnected digital ecosystems and the speed at which a single point of failure can propagate across multiple organizations. The incident's inclusion in TMHCCI's annual report underscored its significance as a defining event of the year, one that will likely inform cybersecurity strategies, underwriting assessments, and integration design practices for years to come.

Sources

Sources available to members: 1 source.

CSIDB