Zscaler Data Breach: Customer Info Exposed After Salesloft Drift Compromise
Summary of the Salesloft/Drift Salesforce Data Breach
This text details a data breach impacting Salesforce instances, stemming from a compromise of Salesloft and its integration with Drift. Here’s a breakdown of the key facts:
What happened?
Compromise of Salesloft/Drift: Threat actors exploited a vulnerability in Salesloft, specifically its integration with Drift (and later Drift Email), to gain access to Salesforce instances.
Data Theft: The attackers stole data from support cases within these Salesforce instances, including authentication tokens, passwords, AWS access keys, and Snowflake access tokens.
Extortion: The stolen data is being used for extortion attempts against companies.
Google Workspace Access: Stolen OAuth tokens were used to access Google Workspace email accounts and read emails.
Who is responsible?
UNC6395: A threat actor group identified by Google Threat Intelligence as being behind the attacks.
ShinyHunters: Some researchers believe this compromise overlaps with attacks attributed to the ShinyHunters extortion group.
How did it happen?
Social Engineering (Vishing): Attackers used voice phishing (vishing) to trick employees into linking malicious OAuth apps to their Salesforce instances.
OAuth Token Exploitation: Once linked, the attackers used the connection to download and steal databases.
Supply Chain Attack: The initial compromise occurred through Salesloft, impacting its integrations with Drift.
What is being done?
Zscaler response: Zscaler states the breach only impacts its Salesforce instance, not its products/services.Thay’ve revoked Salesloft Drift integrations, rotated API tokens, and are investigating. They’ve also strengthened customer authentication protocols.
Google & Salesforce Response: Google and Salesforce have temporarily disabled their Drift integrations.
Customer Suggestion: Zscaler recommends customers remain vigilant against phishing and social engineering attacks.
Log Review: Organizations are advised to review logs for evidence of data exposure.
key Takeaways:
This is a complex attack leveraging social engineering and supply chain vulnerabilities. The attackers are actively exploiting stolen credentials for financial gain.
Companies using Salesloft and Drift, especially with Salesforce integrations, should be aware of the risks and take appropriate security measures.
* The attacks have been ongoing since the beginning of the year and have impacted multiple organizations.
