ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift Supply-Chain Compromise Targeting Salesforce Environments
ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift (TL-2026-1711), also tracked as Salesloft Drift Breach, is a critical-severity supply-chain compromise, first published 2026-07-26. It is attributed to ShinyHunters with high confidence, affects Salesforce Salesforce CRM / Sales Cloud (Connected Apps / OAuth Device, maps to 20 MITRE ATT&CK techniques (T1036, T1070, T1078), and is covered by 9 detection rules and 34 indicators of compromise.
Key facts for TL-2026-1711
- Threat ID
- TL-2026-1711
- Also known as
- Salesloft Drift Breach, Salesforce Vishing Campaign, Scattered LAPSUS$ Hunters Salesforce Extortion
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- SUPPLY_CHAIN
- First published
- 2026-07-26
- Last reviewed
- 2026-07-26
- Attribution
- ShinyHunters
- Attribution confidence
- HIGH
- Motivation
- FINANCIAL
- Target sectors
- technology, cybersecurity, retail, luxury goods, insurance, aviation, logistics, automotive, entertainment, financial services
- Target regions
- North America, Europe, Asia-Pacific
- Detection rules
- 9
- Indicators of compromise
- 34
Malware and tooling in ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift
Malware and tooling: AsyncRAT, Custom Python OAuth Device-Flow Application, Salesforce Data Loader (weaponized), Tor Network, TruffleHog - S9009
Two overlapping 2025 criminal campaigns compromised Salesforce environments at scale: UNC6040 used IT-support vishing calls to trick employees into authorizing a weaponized Salesforce Data Loader OAuth Device Flow app, exfiltrated CRM data, and issued Bitcoin ransom demands under the ShinyHunters/UNC6240 name. Separately, UNC6395 compromised Salesloft's GitHub account (March-June 2025), pivoted into Drift's AWS environment to steal Drift-Salesforce OAuth/refresh tokens, and exfiltrated data from dozens of customer Salesforce instances via Tor between August 8-18, 2025 -- hitting Cloudflare, Tenable, Palo Alto Networks, Zscaler, and many others. Both clusters converged in an October 2025 mass-extortion campaign run by the 'Scattered LAPSUS$ Hunters' collective (ShinyHunters + Scattered Spider + Lapsus$).
How ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift works
This threat covers two technically distinct but operationally converging non-malware, identity-centric campaigns against the Salesforce SaaS ecosystem in 2025.
Campaign 1 -- UNC6040 (publicly reported by Google Threat Intelligence Group in June 2025): a financially motivated cluster specializing in voice phishing (vishing). Operators call English-speaking employees at multinational organizations, impersonate internal IT support, and talk the victim through authorizing a connected application in their company's Salesforce org. The group's signature technique abuses Salesforce's OAuth Device Flow: the attacker pre-configures a local instance of the (initially unmodified, later custom-built Python) Salesforce Data Loader tool, which generates an 8-character device code. The victim, believing they are completing an IT-support-directed setup step, is guided to Salesforce's legitimate device-verification page, enters the code, and authenticates -- silently issuing an OAuth access token to the attacker's Data Loader instance. The tool then listens for the successful authentication and begins slow, low-and-slow data exfiltration to avoid detection, later escalating to full-table exports once verified. UNC6040 also harvested credentials and MFA approvals directly during vishing calls for lateral movement into Okta and Microsoft 365. Google's own corporate Salesforce instance was compromised via this technique in June 2025. Extortion follow-up, tracked separately by Google as UNC6240, arrives weeks to months later via email/phone, demanding 4-20 BTC within 72 hours and invoking the ShinyHunters name.
Campaign 2 -- UNC6395: threat actors gained unauthorized access to Salesloft's GitHub organization between approximately March and June 2025, downloading private repository content as ZIP archives, adding a guest user, and conducting reconnaissance across both the Salesloft and Drift (Salesloft's AI-powered sales-engagement/chat product) application environments. This access was later used to pivot into Drift's AWS environment, where the actor obtained OAuth and refresh tokens issued for Drift's Salesforce, Google Workspace, Outlook, and other customer integrations. Beginning August 8, 2025 (confirmed exfiltration August 12-18), UNC6395 used the stolen Drift-Salesforce tokens to run systematic SOQL reconnaissance (COUNT() queries against Account, Opportunity, User, and Case objects) followed by bulk exports, specifically hunting exported data for AWS access keys (AKIA-prefixed), Snowflake tokens, plaintext passwords, and internal VPN/SSO URLs for follow-on access. The actor deleted its own Salesforce query jobs to reduce forensic visibility and routed exfiltration traffic through Tor exit nodes to complicate attribution. On August 9, compromised 'Drift Email' tokens were separately used to access a limited set of customer Google Workspace accounts. Salesloft and Salesforce revoked all Drift OAuth/refresh tokens and pulled Drift from the AppExchange on August 20, 2025; Google's Threat Intelligence Group published a public UNC6395 advisory on August 26, with scope expanded on August 28 to confirm impact beyond the core Salesforce integration.
Dozens of organizations across technology, cybersecurity, retail/luxury, insurance, aviation, and logistics sectors confirmed impact from the Drift token theft, including Cloudflare (104 exposed API tokens, rotated), Tenable, Palo Alto Networks, Zscaler, PagerDuty, SpyCloud, Proofpoint, Rubrik, Allianz Life, and Farmers Insurance. The FBI issued a FLASH/IC3 advisory (CSA-250912) on September 12, 2025 covering both clusters. In October 2025, a collective calling itself 'Scattered LAPSUS$ Hunters' -- claiming joint ShinyHunters, Scattered Spider, and Lapsus$ membership -- launched a Tor-hosted extortion/leak site listing over three dozen Salesforce victims (including Toyota, FedEx, Disney/Hulu, UPS, Adidas, Dior, Louis Vuitton, Chanel, Tiffany & Co., Cartier, Qantas, and Air France-KLM), demanding Salesforce itself pay a collective ransom by October 10, 2025 or see all listed customer data leaked. Neither campaign exploited a Salesforce software vulnerability; both are pure identity/OAuth-trust abuse against the SaaS supply chain.
MITRE ATT&CK techniques used in TL-2026-1711
Defense Evasion
T1036 Masquerading; T1070 Indicator Removal; T1078 Valid Accounts
Initial Access
T1078 Valid Accounts; T1199 Trusted Relationship; T1566 Phishing
Privilege Escalation
Discovery
T1087 Account Discovery; T1526 Cloud Service Discovery
command-and-control
Persistence
Collection
T1213 Data from Information Repositories; T1530 Data from Cloud Storage
Exfiltration
T1537 Transfer Data to Cloud Account; T1567 Exfiltration Over Web Service
lateral-movement
T1550 Use Alternate Authentication Material
Credential Access
T1552 Unsecured Credentials; T1621 Multi-Factor Authentication Request Generation
Resource Development
T1583 Acquire Infrastructure; T1588 Obtain Capabilities
Reconnaissance
T1589 Gather Victim Identity Information
Impact
Affected products and versions in ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift
- Salesforce — Salesforce CRM / Sales Cloud (Connected Apps / OAuth Device Flow)
Vulnerable versions: Any customer org with Connected App / OAuth Device Flow authorization enabled, targeted March-October 2025
Fixed in: N/A -- identity-process abuse, not a software vulnerability; mitigated via Connected App policy hardening and token revocation - Salesloft — Drift (AI chat / sales-engagement platform) -- Salesforce, Google Workspace, Outlook integrations
Vulnerable versions: All active Drift-Salesforce and Drift-Google Workspace integrations, March-August 2025
Fixed in: Drift removed from the Salesforce AppExchange; all OAuth/refresh tokens revoked August 20, 2025; Mandiant-verified containment - Salesloft — Salesloft GitHub organization (private repositories)
Vulnerable versions: Salesloft GitHub account, unauthorized access window March-June 2025
Fixed in: Access revoked; guest user removed; workflows audited post-incident
Remediation for ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift
Patches
- No vendor patch applies -- this is a process/identity-trust compromise, not a software vulnerability
Immediate actions
- Revoke and rotate ALL Drift/Salesloft-issued OAuth and refresh tokens; treat every token that ever transited Drift as compromised
- Revoke and rotate any AWS access keys (AKIA*), Snowflake tokens, passwords, or SSO/VPN URLs discoverable in Salesforce Case, User, Account, or Opportunity object data
- Audit and remove the legitimate Salesforce Data Loader connected app and any unrecognized connected apps from org Setup > Connected Apps
- Open a Salesforce support case to obtain the threat actor's specific historical SOQL query log for the affected org
Workarounds
- Set Connected App 'IP Relaxation' to 'Enforce IP restrictions' and define Login IP Ranges at the profile level
- Configure aggressive Salesforce session-timeout values to shrink the OAuth token compromise window
- Block or step-up-challenge authentication attempts and connected-app authorizations originating from Tor exit nodes and commercial VPN ranges (e.g., Mullvad)
- Disable third-party connected apps (Drift and equivalents) pending vendor confirmation of remediation and re-scoped OAuth permissions
Longer-term hardening
- Restrict 'API Enabled' permission to only roles that require it via dedicated Permission Sets, never broad Profiles
- Enforce Connected App allowlisting with mandatory admin pre-approval workflows
- Restrict 'Customize Application' and 'Manage Connected Apps' permissions to a minimal admin group
- Deploy Salesforce Shield Event Monitoring / Transaction Security Policies to alert on bulk export volume, anomalous API usage, and large SOQL COUNT()-then-export patterns
- Mandate security-awareness training on IT-support vishing pretexts and OAuth device-code social engineering
Timeline of ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift
- UNC6395 gains unauthorized access to Salesloft's GitHub account, beginning a multi-month reconnaissance and repository-download campaign (access window: March-June 2025).
- Google's own corporate Salesforce instance is compromised by UNC6040 using the same vishing/OAuth Device Flow technique; contact-info and business-note data accessed.
- Google Threat Intelligence Group (GTIG) publicly discloses UNC6040's Salesforce vishing / Data Loader OAuth Device Flow abuse campaign.
- UNC6395 begins large-scale data exfiltration from customer Salesforce environments using stolen Salesloft Drift OAuth/refresh tokens (active exfiltration window: Aug 8-18, 2025).
- Compromised 'Drift Email' OAuth tokens are used to access a limited set of customer Google Workspace accounts integrated with Drift.
- Tor exit-node-based exfiltration traffic against victim Salesforce instances is confirmed via abnormally high-volume GET request patterns.
- Salesloft and Salesforce revoke all active Drift OAuth/refresh tokens; the Drift application is pulled from the Salesforce AppExchange.
- Cloudflare is notified by Salesloft/Salesforce of the compromise affecting its Salesforce support-case data, including 104 exposed API tokens.
- GTIG publishes its public advisory formally attributing the Drift/Salesforce data-theft campaign to UNC6395.
- Investigation update confirms breach scope extends beyond the core Salesforce integration to other Drift-connected third-party applications.
- Cloudflare, Zscaler, Palo Alto Networks, Tenable, and other Fortune 500 organizations publicly confirm they were impacted by the Salesloft Drift token theft.
- The FBI issues a FLASH/IC3 advisory (CSA-250912) describing both the UNC6040 vishing campaign and the UNC6395 Salesloft Drift supply-chain compromise.
- 'Scattered LAPSUS$ Hunters' (claiming ShinyHunters, Scattered Spider, and Lapsus$ membership) launches a Tor-hosted leak site listing over three dozen Salesforce victims, including Toyota, FedEx, Disney/Hulu, and UPS.
- Scattered LAPSUS$ Hunters' deadline for Salesforce to pay a collective ransom on behalf of listed victims passes; leak-site pressure campaign continues.
Sources cited for ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift
- ShinyHunters and UNC6395: Inside the Salesforce and Salesloft Breaches
- Data Theft from Salesforce Instances via Salesloft Drift
- Voice Phishing and Data Extortion: UNC6040 Targets Salesforce
- Google Exposes Vishing Group UNC6040 Targeting Salesforce with Fake Data Loader App
- GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies
- ShinyHunters Wage Broad Corporate Extortion Spree
- Salesloft Drift attacks hit Cloudflare, Palo Alto Networks, Zscaler
- Cloudflare hit by data breach in Salesloft Drift supply chain attack
- Salesloft GitHub Account Compromised Months Before Salesforce Attack
- Scattered Lapsus$ Hunters Drops Salesforce Leak Site
- Scattered Lapsus$ Hunters
- FBI FLASH: Cyber Criminal Groups UNC6040 and UNC6395 Targeting Salesforce Platforms (CSA-250912)
- FBI warns about 2 campaigns targeting Salesforce instances
- Zscaler, Palo Alto Networks, SpyCloud among the affected by Salesloft Drift breach
- Salesloft Drift Attacks Exposed Zscaler Customer Data
Threats related to ShinyHunters (UNC6040) OAuth Abuse & UNC6395 Salesloft/Drift
- Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted
- Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Attack Paths (UNC6040/UNC6240/UNC6395/GRUB1/Storm-3138)
- ShinyHunters (UNC6040/UNC6395) OAuth Consent Abuse Against Salesforce and Connected SaaS Integrations
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering
- LastPass Customer CRM Data Exposed via Klue OAuth Token Theft (Icarus Salesforce Supply-Chain Campaign)
- Klue Supply Chain Breach: OAuth Token Harvesting & Salesforce CRM Data Exfiltration
Detection coverage for TL-2026-1711
As of 2026-07-26, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1711 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1711
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.