{"id":40754,"date":"2025-09-02T14:34:08","date_gmt":"2025-09-02T21:34:08","guid":{"rendered":"https:\/\/salesforcedevops.net\/?p=40754"},"modified":"2025-09-02T14:34:13","modified_gmt":"2025-09-02T21:34:13","slug":"salesforce-under-siege","status":"publish","type":"post","link":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/","title":{"rendered":"Salesforce Under Siege: 2025\u2019s Wave of OAuth Abuse and ISV Breaches"},"content":{"rendered":"\n<p class=\"has-drop-cap wp-block-paragraph\">Salesforce environments and their ecosystem of ISVs have become a prime target for cybercriminals in 2025. Two distinct attack patterns emerged this year. First <strong><a href=\"https:\/\/salesforcedevops.net\/index.php\/2025\/08\/17\/salesforce-customers-fall-victim-as-shinyhunters-and-scattered-spider-join-forces\/\">ShinyHunters\u2019 OAuth token abuse campaign<\/a><\/strong>, which infiltrated multiple Salesforce customer orgs through malicious connected apps. Next <strong>The Salesloft Drift breach<\/strong>, a supply-chain attack where attackers stole OAuth tokens en masse from a popular ISV integration.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Together, these incidents reveal how attackers bypass traditional defenses like MFA and focusing instead on weak spots in <strong>OAuth integrations<\/strong> and <strong>user trust<\/strong>.<\/p>\n\n\n\n<div class=\"wp-block-yoast-seo-table-of-contents yoast-table-of-contents\"><h2>Table of contents<\/h2><ul><li><a href=\"#h-the-shinyhunters-campaign-social-engineering-meets-oauth\" data-level=\"2\">The ShinyHunters Campaign: Social Engineering Meets OAuth<\/a><\/li><li><a href=\"#h-salesloft-drift-a-supply-chain-breach-at-scale\" data-level=\"2\">Salesloft Drift: A Supply-Chain Breach at Scale<\/a><\/li><li><a href=\"#h-case-in-point-cloudflare\" data-level=\"2\">Case in Point: Cloudflare<\/a><\/li><li><a href=\"#h-containment-measures\" data-level=\"2\">Containment Measures<\/a><\/li><li><a href=\"#h-lessons-for-the-ecosystem\" data-level=\"2\">Lessons for the Ecosystem<\/a><\/li><li><a href=\"#h-key-takeaways\" data-level=\"2\">Key Takeaways<\/a><\/li><li><a href=\"#h-what-enterprises-should-do\" data-level=\"2\">What Enterprises Should Do<\/a><\/li><li><a href=\"#h-why-this-matters\" data-level=\"2\">Why This Matters<\/a><\/li><\/ul><\/div>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-the-shinyhunters-campaign-social-engineering-meets-oauth\">The ShinyHunters Campaign: Social Engineering Meets OAuth<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Beginning in the spring, threat group <strong>ShinyHunters<\/strong> executed a wave of Salesforce data thefts through a clever social engineering play. By impersonating IT help desk staff, attackers tricked employees into authorizing a <strong>malicious Salesforce connected app<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Once the app was authorized, attackers gained a <strong>long-lived OAuth refresh token<\/strong>, allowing them to pull data via Salesforce APIs indefinitely\u2014without needing passwords or triggering MFA.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Notable Victims<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Farmers Insurance<\/strong> \u2013 1.1M customer records exposed (May 2025)<\/li>\n\n\n\n<li><strong>Coca-Cola Europacific Partners<\/strong> \u2013 23M Salesforce records stolen<\/li>\n\n\n\n<li><strong>Allianz Life<\/strong> \u2013 most of 1.4M customer records compromised (July)<\/li>\n\n\n\n<li><strong>Google Ads Salesforce instance<\/strong> \u2013 2.55M business contacts taken<\/li>\n\n\n\n<li><strong>Chanel, LVMH, Adidas, Qantas<\/strong> \u2013 customer data quietly siphoned<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The fallout was significant: customer PII was stolen, extortion attempts were made, and in several cases (e.g., Allianz, Chanel), stolen data later appeared on underground forums.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-salesloft-drift-a-supply-chain-breach-at-scale\">Salesloft Drift: A Supply-Chain Breach at Scale<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In August, the focus shifted from social engineering to a <strong>direct ISV compromise<\/strong>. Attackers identified as <strong>UNC6395<\/strong> infiltrated Salesloft\u2019s <em>Drift<\/em> integration and stole <strong>OAuth tokens<\/strong> tied to Salesforce connections.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With these tokens, the attackers impersonated Drift\u2019s app in hundreds of Salesforce orgs, exfiltrating customer support cases, leads, and contact records. The scope was wide, with security vendors like <strong>Cloudflare<\/strong>, <strong>Zscaler<\/strong>, and <strong>SpyCloud<\/strong> confirming impacts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-case-in-point-cloudflare\">Case in Point: Cloudflare<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Between August 12\u201317, attackers pulled entire support case histories from Cloudflare\u2019s Salesforce instance. Buried in those cases were <strong>104 customer API tokens<\/strong>, which Cloudflare immediately revoked and rotated. The attackers also combed through data for AWS keys, passwords, and other cloud credentials\u2014hinting at a motive of <strong>credential harvesting for future intrusions<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-containment-measures\">Containment Measures<\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Aug. 20: Salesforce and Salesloft revoked all Drift tokens and pulled the app from AppExchange.<\/li>\n\n\n\n<li>Aug. 28: Salesforce went further, disabling <em>all Salesloft integrations<\/em> platform-wide.<\/li>\n\n\n\n<li>Google revoked associated Gmail Drift tokens after detecting related compromise.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-lessons-for-the-ecosystem\">Lessons for the Ecosystem<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">These incidents illustrate a broader truth: <strong>Salesforce itself was not breached<\/strong>. Instead, attackers exploited <strong>the weakest links\u2014users and ISVs.<\/strong> It\u2019s that good old Shared Security Model biting users in the butt once again.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-key-takeaways\">Key Takeaways<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Here are the key lessons from this event.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Salesforce security awareness matters.<\/strong> Many Salesforce sites lack the professional awareness and auditing skills required to keep sites safe. Think about upgrading your skills and staffing.<\/li>\n\n\n\n<li><strong>OAuth tokens are the new crown jewels.<\/strong> Once issued, they bypass MFA and give API-level access that is hard to monitor.<\/li>\n\n\n\n<li><strong>ISVs are part of your attack surface.<\/strong> The Salesloft case shows how one vendor compromise can cascade across hundreds of orgs.<\/li>\n\n\n\n<li><strong>User training still matters.<\/strong> ShinyHunters succeeded by convincing employees to authorize apps.<\/li>\n\n\n\n<li><strong>Audit your connected apps.<\/strong> Few enterprises monitor OAuth grants closely, leaving attackers with a blind spot to exploit.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-what-enterprises-should-do\">What Enterprises Should Do<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Besides taking advantage of SaaS Security Posture Management (SSPM) packages like AutoRABIT Guard or AppOmni, here are some immediate actions you should take to keep your Salesforce instance safe.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Audit all <strong>Salesforce connected apps<\/strong> for scope and necessity.<\/li>\n\n\n\n<li>Revoke unused OAuth tokens; rotate credentials regularly.<\/li>\n\n\n\n<li>Apply <strong>least-privilege scopes<\/strong> and IP restrictions on integrations.<\/li>\n\n\n\n<li>Monitor for anomalies: sudden surges in SOQL queries, API calls, or new app authorizations.<\/li>\n\n\n\n<li>Train staff to treat any \u201cIT support\u201d request for Salesforce codes or integrations with extreme caution.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-this-matters\">Why This Matters<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The <strong>2025 Salesforce attacks<\/strong> mark a turning point. Cybercriminals are moving from password theft to <strong>integration abuse<\/strong>. As enterprise SaaS ecosystems grow more interconnected, attackers will increasingly target the seams\u2014OAuth, ISVs, and help-desk trust.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Salesforce customers and ISVs alike must treat OAuth governance and ISV security posture as first-class priorities. Otherwise, the next spree will make 2025 look like a rehearsal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<ul class=\"wp-block-yoast-seo-related-links yoast-seo-related-links\">\n<li><a href=\"https:\/\/salesforcedevops.net\/index.php\/2022\/04\/05\/how-to-use-github-actions-oauth-and-sfdx-cli-for-continuous-integration\/\">How To Use GitHub Actions, OAuth and SFDX-CLI for Continuous Integration<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/salesforcedevops.net\/index.php\/2025\/08\/17\/salesforce-customers-fall-victim-as-shinyhunters-and-scattered-spider-join-forces\/\">Salesforce Customers Fall Victim as ShinyHunters and Scattered Spider Join Forces<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/09\/salesforce-bruised-over-heroku-breach-response\/\">Salesforce Bruised over Heroku Breach Response<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/salesforcedevops.net\/index.php\/2022\/05\/23\/heroku-breach-update-opsera-delivers-devops-secrets-management\/\">Heroku Breach Update, Opsera Delivers Devops Secrets Management<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/salesforcedevops.net\/index.php\/2024\/09\/25\/disneys-slack-breach\/\">Disney\u2019s Slack Breach: A Wake-Up Call for the Shared Responsibility Model<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Salesforce environments and their ecosystem of ISVs have become a prime target for cybercriminals in 2025. Two distinct attack patterns emerged this year. First ShinyHunters\u2019 OAuth token abuse campaign, which&hellip;<\/p>\n","protected":false},"author":1,"featured_media":40756,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_uag_custom_page_level_css":"","footnotes":""},"categories":[4],"tags":[],"post_series":[],"class_list":["post-40754","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-news","entry","has-media"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.9 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Salesforce Under Siege: 2025\u2019s Wave of OAuth Abuse and ISV Breaches - SalesforceDevops.net<\/title>\n<meta name=\"description\" content=\"In 2025, Salesforce customers and ISVs faced a wave of OAuth token abuse and supply-chain breaches, including the Salesloft Drift incident.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Salesforce Under Siege: 2025\u2019s Wave of OAuth Abuse and ISV Breaches - SalesforceDevops.net\" \/>\n<meta property=\"og:description\" content=\"In 2025, Salesforce customers and ISVs faced a wave of OAuth token abuse and supply-chain breaches, including the Salesloft Drift incident.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/\" \/>\n<meta property=\"og:site_name\" content=\"SalesforceDevops.net\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/salesforcedevopsnet\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-02T21:34:08+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-02T21:34:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1169\" \/>\n\t<meta property=\"og:image:height\" content=\"658\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Vernon Keenan\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@salesforcedevop\" \/>\n<meta name=\"twitter:site\" content=\"@salesforcedevop\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Vernon Keenan\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"TechArticle\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2025\\\/09\\\/02\\\/salesforce-under-siege\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2025\\\/09\\\/02\\\/salesforce-under-siege\\\/\"},\"author\":{\"name\":\"Vernon Keenan\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#\\\/schema\\\/person\\\/f681893c994bc40406bb391546cd7ac8\"},\"headline\":\"Salesforce Under Siege: 2025\u2019s Wave of OAuth Abuse and ISV Breaches\",\"datePublished\":\"2025-09-02T21:34:08+00:00\",\"dateModified\":\"2025-09-02T21:34:13+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2025\\\/09\\\/02\\\/salesforce-under-siege\\\/\"},\"wordCount\":774,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2025\\\/09\\\/02\\\/salesforce-under-siege\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/exfiltration-cover.jpg\",\"articleSection\":[\"Industry News\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2025\\\/09\\\/02\\\/salesforce-under-siege\\\/#respond\"]}],\"copyrightYear\":\"2025\",\"copyrightHolder\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#organization\"},\"accessibilityFeature\":[\"tableOfContents\"]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2025\\\/09\\\/02\\\/salesforce-under-siege\\\/\",\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2025\\\/09\\\/02\\\/salesforce-under-siege\\\/\",\"name\":\"Salesforce Under Siege: 2025\u2019s Wave of OAuth Abuse and ISV Breaches - SalesforceDevops.net\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2025\\\/09\\\/02\\\/salesforce-under-siege\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2025\\\/09\\\/02\\\/salesforce-under-siege\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/exfiltration-cover.jpg\",\"datePublished\":\"2025-09-02T21:34:08+00:00\",\"dateModified\":\"2025-09-02T21:34:13+00:00\",\"description\":\"In 2025, Salesforce customers and ISVs faced a wave of OAuth token abuse and supply-chain breaches, including the Salesloft Drift incident.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2025\\\/09\\\/02\\\/salesforce-under-siege\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/2025\\\/09\\\/02\\\/salesforce-under-siege\\\/#primaryimage\",\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/exfiltration-cover.jpg\",\"contentUrl\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/exfiltration-cover.jpg\",\"width\":1169,\"height\":658,\"caption\":\"Stylized illustration of cybercriminals siphoning data through glowing pipelines connected to a cloud, symbolizing Salesforce integration attacks and OAuth token breaches\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#website\",\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/\",\"name\":\"SalesforceDevops.net\",\"description\":\"Elevating Salesforce Devops with Insights and Innovation\",\"publisher\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/salesforcedevops.net\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#organization\",\"name\":\"SalesforceDevops.net\",\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/7760e9c16fc75961659174739887197e-sticker.png\",\"contentUrl\":\"https:\\\/\\\/salesforcedevops.net\\\/wp-content\\\/uploads\\\/2021\\\/03\\\/7760e9c16fc75961659174739887197e-sticker.png\",\"width\":421,\"height\":421,\"caption\":\"SalesforceDevops.net\"},\"image\":{\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/salesforcedevopsnet\",\"https:\\\/\\\/x.com\\\/salesforcedevop\",\"https:\\\/\\\/www.linkedin.com\\\/in\\\/vernonkeenan\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCOgOn9rD5gyXSOmV7-Q0n7g\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/salesforcedevops.net\\\/#\\\/schema\\\/person\\\/f681893c994bc40406bb391546cd7ac8\",\"name\":\"Vernon Keenan\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g\",\"caption\":\"Vernon Keenan\"},\"description\":\"Vernon Keenan (LinkedIn) works as a senior information technology industry consultant based in Oakland, California. He earned his B.Sc. in Biomedical Engineering at Northwestern University where he programmed a PDP-8 with punched paper tape. In his 34-year-long career he has been a teacher, SPSS programmer, database administrator, clinical researcher, technology journalist, product marketing manager, market researcher, management consultant, and industry analyst. Most recently he is a telecom operator, cloud architect, Go devops engineer and Salesforce Developer\\\/Architect. For inquiries about Salesforce strategy briefings or solution architect work please contact Vern directly at +1-510-679-1900 or vern@vernonkeenan.com.\",\"sameAs\":[\"https:\\\/\\\/ceres-gw.tnxs.net\",\"https:\\\/\\\/linkedin.com\\\/in\\\/vernonkeenan\",\"https:\\\/\\\/x.com\\\/salesforcedevop\"],\"url\":\"https:\\\/\\\/salesforcedevops.net\\\/index.php\\\/author\\\/vern\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Salesforce Under Siege: 2025\u2019s Wave of OAuth Abuse and ISV Breaches - SalesforceDevops.net","description":"In 2025, Salesforce customers and ISVs faced a wave of OAuth token abuse and supply-chain breaches, including the Salesloft Drift incident.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/","og_locale":"en_US","og_type":"article","og_title":"Salesforce Under Siege: 2025\u2019s Wave of OAuth Abuse and ISV Breaches - SalesforceDevops.net","og_description":"In 2025, Salesforce customers and ISVs faced a wave of OAuth token abuse and supply-chain breaches, including the Salesloft Drift incident.","og_url":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/","og_site_name":"SalesforceDevops.net","article_publisher":"https:\/\/www.facebook.com\/salesforcedevopsnet","article_published_time":"2025-09-02T21:34:08+00:00","article_modified_time":"2025-09-02T21:34:13+00:00","og_image":[{"width":1169,"height":658,"url":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg","type":"image\/jpeg"}],"author":"Vernon Keenan","twitter_card":"summary_large_image","twitter_creator":"@salesforcedevop","twitter_site":"@salesforcedevop","twitter_misc":{"Written by":"Vernon Keenan","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"TechArticle","@id":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/#article","isPartOf":{"@id":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/"},"author":{"name":"Vernon Keenan","@id":"https:\/\/salesforcedevops.net\/#\/schema\/person\/f681893c994bc40406bb391546cd7ac8"},"headline":"Salesforce Under Siege: 2025\u2019s Wave of OAuth Abuse and ISV Breaches","datePublished":"2025-09-02T21:34:08+00:00","dateModified":"2025-09-02T21:34:13+00:00","mainEntityOfPage":{"@id":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/"},"wordCount":774,"commentCount":0,"publisher":{"@id":"https:\/\/salesforcedevops.net\/#organization"},"image":{"@id":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/#primaryimage"},"thumbnailUrl":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg","articleSection":["Industry News"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/#respond"]}],"copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/salesforcedevops.net\/#organization"},"accessibilityFeature":["tableOfContents"]},{"@type":"WebPage","@id":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/","url":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/","name":"Salesforce Under Siege: 2025\u2019s Wave of OAuth Abuse and ISV Breaches - SalesforceDevops.net","isPartOf":{"@id":"https:\/\/salesforcedevops.net\/#website"},"primaryImageOfPage":{"@id":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/#primaryimage"},"image":{"@id":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/#primaryimage"},"thumbnailUrl":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg","datePublished":"2025-09-02T21:34:08+00:00","dateModified":"2025-09-02T21:34:13+00:00","description":"In 2025, Salesforce customers and ISVs faced a wave of OAuth token abuse and supply-chain breaches, including the Salesloft Drift incident.","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/salesforcedevops.net\/index.php\/2025\/09\/02\/salesforce-under-siege\/#primaryimage","url":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg","contentUrl":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg","width":1169,"height":658,"caption":"Stylized illustration of cybercriminals siphoning data through glowing pipelines connected to a cloud, symbolizing Salesforce integration attacks and OAuth token breaches"},{"@type":"WebSite","@id":"https:\/\/salesforcedevops.net\/#website","url":"https:\/\/salesforcedevops.net\/","name":"SalesforceDevops.net","description":"Elevating Salesforce Devops with Insights and Innovation","publisher":{"@id":"https:\/\/salesforcedevops.net\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/salesforcedevops.net\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/salesforcedevops.net\/#organization","name":"SalesforceDevops.net","url":"https:\/\/salesforcedevops.net\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/salesforcedevops.net\/#\/schema\/logo\/image\/","url":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2021\/03\/7760e9c16fc75961659174739887197e-sticker.png","contentUrl":"https:\/\/salesforcedevops.net\/wp-content\/uploads\/2021\/03\/7760e9c16fc75961659174739887197e-sticker.png","width":421,"height":421,"caption":"SalesforceDevops.net"},"image":{"@id":"https:\/\/salesforcedevops.net\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/salesforcedevopsnet","https:\/\/x.com\/salesforcedevop","https:\/\/www.linkedin.com\/in\/vernonkeenan","https:\/\/www.youtube.com\/channel\/UCOgOn9rD5gyXSOmV7-Q0n7g"]},{"@type":"Person","@id":"https:\/\/salesforcedevops.net\/#\/schema\/person\/f681893c994bc40406bb391546cd7ac8","name":"Vernon Keenan","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f1183f1ebb5c059e052825760f95b25244abc5ef832145327f298f3697f980c7?s=96&d=mm&r=g","caption":"Vernon Keenan"},"description":"Vernon Keenan (LinkedIn) works as a senior information technology industry consultant based in Oakland, California. He earned his B.Sc. in Biomedical Engineering at Northwestern University where he programmed a PDP-8 with punched paper tape. In his 34-year-long career he has been a teacher, SPSS programmer, database administrator, clinical researcher, technology journalist, product marketing manager, market researcher, management consultant, and industry analyst. Most recently he is a telecom operator, cloud architect, Go devops engineer and Salesforce Developer\/Architect. For inquiries about Salesforce strategy briefings or solution architect work please contact Vern directly at +1-510-679-1900 or vern@vernonkeenan.com.","sameAs":["https:\/\/ceres-gw.tnxs.net","https:\/\/linkedin.com\/in\/vernonkeenan","https:\/\/x.com\/salesforcedevop"],"url":"https:\/\/salesforcedevops.net\/index.php\/author\/vern\/"}]}},"uagb_featured_image_src":{"full":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg",1169,658,false],"thumbnail":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover-150x150.jpg",150,150,true],"medium":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover-300x169.jpg",300,169,true],"medium_large":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover-768x432.jpg",768,432,true],"large":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover-1024x576.jpg",980,551,true],"1536x1536":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg",1169,658,false],"2048x2048":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg",1169,658,false],"lightbox":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg",1169,658,false],"search_results":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover-125x125.jpg",125,125,true],"blog_entry":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg",750,422,false],"blog_post":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg",750,422,false],"blog_post_full":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg",1169,658,false],"blog_related":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg",1169,658,false],"gallery":["https:\/\/salesforcedevops.net\/wp-content\/uploads\/2025\/09\/exfiltration-cover.jpg",1169,658,false]},"uagb_author_info":{"display_name":"Vernon Keenan","author_link":"https:\/\/salesforcedevops.net\/index.php\/author\/vern\/"},"uagb_comment_info":1,"uagb_excerpt":"Salesforce environments and their ecosystem of ISVs have become a prime target for cybercriminals in 2025. Two distinct attack patterns emerged this year. First ShinyHunters\u2019 OAuth token abuse campaign, which&hellip;","_links":{"self":[{"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/posts\/40754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/comments?post=40754"}],"version-history":[{"count":2,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/posts\/40754\/revisions"}],"predecessor-version":[{"id":40757,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/posts\/40754\/revisions\/40757"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/media\/40756"}],"wp:attachment":[{"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/media?parent=40754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/categories?post=40754"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/tags?post=40754"},{"taxonomy":"post_series","embeddable":true,"href":"https:\/\/salesforcedevops.net\/index.php\/wp-json\/wp\/v2\/post_series?post=40754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}