National Cyber Warfare Foundation (NCWF)

Hackers Abuse Compromised OAuth Tokens to Access and Steal Salesforce Corporate Data


0 user ratings
2025-08-27 06:09:12
milo
Red Team (CNA)

Google Threat Intelligence Group (GTIG) has issued an advisory concerning a broad data theft operation targeting corporate Salesforce instances via the Drift integration. Beginning as early as August 8, 2025, UNC6395 leveraged valid access and refresh tokens associated with the Salesloft Drift app to connect as an authenticated connected app user, executing large-scale SOQL queries […]


The post Hackers Abuse Compromised OAuth Tokens to Access and Steal Salesforce Corporate Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.



Divya

Source: gbHackers
Source Link: https://gbhackers.com/hackers-abuse-compromised-oauth-tokens/


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Red Team (CNA)



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.