Google Workspace Breach Impacts Some Accounts
- Google has expanded its warning regarding the recent data breach affecting Salesloft Drift customers.
- The campaign, tracked as UNC6395 by Mandiant (now part of Google Cloud), began with the theft of OAuth tokens used for Salesloft's Drift AI chat integration with Salesforce.
- Attackers exploited the compromised OAuth tokens to execute queries against Salesforce objects.
“`html
Salesloft Drift Breach Expands: Google Warns of Compromised OAuth Tokens and Google Workspace Access
What Happened?
Google has expanded its warning regarding the recent data breach affecting Salesloft Drift customers. Initial reports focused on unauthorized access to Salesforce instances via compromised OAuth tokens.Google now confirms that attackers leveraged these stolen tokens to access a limited number of Google Workspace email accounts as well.GoogleS Threat Intelligence Group (GTIG) detailed the expanded scope on August 29, 2024.
The campaign, tracked as UNC6395 by Mandiant (now part of Google Cloud), began with the theft of OAuth tokens used for Salesloft’s Drift AI chat integration with Salesforce. These tokens granted attackers access to customer Salesforce data, specifically targeting tables containing information on Cases, Accounts, Users, and Opportunities.
What Data Was Compromised?
Attackers exploited the compromised OAuth tokens to execute queries against Salesforce objects. The specific data accessed included:
- Cases: Customer support and issue tracking data.
- Accounts: Information about customer organizations.
- Users: Details about individuals associated with those accounts.
- Opportunities: Sales pipeline and potential deal information.
Moreover, Google now advises that any authentication tokens stored within or connected to the Drift platform should be considered potentially compromised, raising concerns about broader access beyond Salesforce.
Who is Affected?
the primary group affected are customers of Salesloft Drift who utilize the Salesforce integration. Though, the expanded scope of the breach, including potential access to Google Workspace accounts, broadens the impact. Any organization using Salesloft Drift and relying on OAuth authentication for other services should review their security posture.
Timeline of Events
| Date | Event |
|---|---|
| August 26, 2024 | Initial disclosure of the Salesloft Drift breach and unauthorized access to Salesforce instances. |
| August 29, 2024 | Google publishes a blog post detailing the expanded scope of the breach, including potential Google Workspace access. |
What Does This Mean?
The expanded scope of the breach underscores the importance of treating all authentication tokens as potentially compromised. Organizations should instantly revoke and reissue any tokens associated with the Drift platform.This incident also serves as a reminder of the potential for lateral movement within cloud environments,where attackers can leverage compromised credentials to access multiple services.
What’s Next?
Salesloft and Google are continuing to investigate the incident and work with affected customers. Organizations should:
- Revoke and reissue all Salesloft Drift OAuth tokens.
- Review audit logs for suspicious activity in both Salesforce and Google Workspace.
- Implement multi-factor authentication (MFA) for all user accounts.
- monitor for any signs of data exfiltration or unauthorized access.
