• Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE
No Result
View All Result
Sumtrix
No Result
View All Result
Home Cyber

Google Warns Data Theft from ‘Salesloft Drift’ AI Agent Has Grown Bigger

Jane Doe by Jane Doe
August 30, 2025
in Cyber
Google Warns Data Theft from ‘Salesloft Drift’ AI Agent Has Grown Bigger
Share on FacebookShare on Twitter

Google Threat Intelligence Group (GTIG), in collaboration with Mandiant, has issued an urgent warning to organizations worldwide, revealing that a widespread data theft campaign originating from the ‘Salesloft Drift’ AI agent is more extensive than initially believed. The campaign, which is being attributed to the threat actor tracked as UNC6395, has resulted in the compromise of hundreds of Salesforce customer instances and, more recently, a limited number of Google Workspace accounts.

The attacks, which occurred between August 8 and August 18, 2025, exploited compromised OAuth tokens associated with the Salesloft Drift third-party application. Rather than directly breaching the core platforms, the threat actor leveraged the app’s compromised connection to systematically exfiltrate vast amounts of data. According to GTIG, the primary objective of the campaign was to “harvest credentials” and other sensitive information, including AWS access keys, passwords, and Snowflake-related tokens, to enable further attacks on victim environments.

Initial investigations focused on the Salesforce integration, but Google’s latest advisory confirms that the scope extends to other integrations. The threat actor also used stolen OAuth tokens from the “Drift Email” integration to access a small number of Google Workspace email accounts. Google has clarified that this was not a compromise of its core platforms but a vulnerability tied to the specific third-party app integration.

Read

App Store Power and Censorship: How Apple and Google Shape Your Digital Future

Google Sets Sights on Defying Gravity with Antigravity Project

In response to the escalating threat, Google has taken swift action, revoking the compromised OAuth tokens, disabling the affected integration with Google Workspace, and notifying all impacted administrators. Both Google and Salesloft are urging all customers to treat any and all authentication tokens connected to the Drift platform as potentially compromised.

This incident highlights a growing vulnerability in the interconnected SaaS ecosystem, where the security of one third-party application can become a weak point for multiple, business-critical platforms. Cybersecurity experts emphasize the need for organizations to conduct thorough reviews of all third-party integrations, revoke and rotate credentials, and diligently investigate their logs for signs of unauthorized access. The campaign underscores that even a single compromised AI agent can serve as a conduit for a much larger and more damaging supply-chain attack.

Previous Post

U.S. and Allies Declare ‘Salt Typhoon’ Hack a National Defense Crisis

Next Post

AI Chatbot Claude Abused to Launch “Cybercrime Spree”

Jane Doe

Jane Doe

More Articles

Operation WrtHug Hijacks Tens of Thousands ASUS Routers
Latest News

Operation WrtHug Hijacks Tens of Thousands ASUS Routers

Massive Infection: Tens of thousands of end-of-life ASUS WRT routers compromised worldwide, mainly in Taiwan, the US, and Russia. Exploit...

by Sumit Chauhan
November 19, 2025
WhatsApp Worm Delivers Brazilian Banking Trojan
Cyber

WhatsApp Worm Delivers Brazilian Banking Trojan

Worm Spread: Python-scripted WhatsApp worm targets Brazil, hijacking accounts to send a Delphi-based banking trojan, Eternidade Stealer. Infection Path: Starts...

by Sumit Chauhan
November 19, 2025
FBI Sounds Alarm on Akira Ransomware’s 0 Million Haul
Cyber

FBI Sounds Alarm on Akira Ransomware’s $250 Million Haul

Ransom Total: $248.9 million from 321 victims—mostly US firms in tech, finance, healthcare since May 2023. Tactics: Double extortion—encrypts files,...

by Max Mueller
November 16, 2025
US Car Dealers Grind to Halt in CDK Ransomware Chaos
Cyber

US Car Dealers Grind to Halt in CDK Ransomware Chaos

Scale Hit: 15,000+ dealerships across US and Canada offline—sales, financing, service apps down for weeks. Financial Sting: $1.2 billion lost...

by Mayank Singh
November 16, 2025
Next Post
AI Chatbot Claude Abused to Launch “Cybercrime Spree”

AI Chatbot Claude Abused to Launch “Cybercrime Spree”

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

Latest News

Hackers Use ‘Ghost Calls’ to Abuse Web Conferencing Platforms for Covert C2

Hackers Use ‘Ghost Calls’ to Abuse Web Conferencing Platforms for Covert C2

August 7, 2025
CKGSB Launches New White Paper on China’s Role in the Global AI Race

CKGSB Launches New White Paper on China’s Role in the Global AI Race

July 1, 2025
Unveiling the Secret Defense Tactics of Four Key Industries Against Cyber Threats

Unveiling the Secret Defense Tactics of Four Key Industries Against Cyber Threats

June 2, 2025
Rethinking Risk: How the GRC Cube Transforms Security Leadership

Rethinking Risk: How the GRC Cube Transforms Security Leadership

May 25, 2025
Stay Safe from Ransomware Using Skitnet Malware Techniques

Stay Safe from Ransomware Using Skitnet Malware Techniques

May 20, 2025
App Store Power and Censorship: How Apple and Google Shape Your Digital Future

App Store Power and Censorship: How Apple and Google Shape Your Digital Future

November 19, 2025
Google Sets Sights on Defying Gravity with Antigravity Project

Google Sets Sights on Defying Gravity with Antigravity Project

November 19, 2025
Sumtrix.com

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Navigate Site

  • About
  • Contact
  • Privacy Policy
  • Advertise

Follow Us

No Result
View All Result
  • Home
  • News
  • AI
  • Cyber
  • GRC
  • Blogs
  • Live CVE

© 2025 Sumtrix – Your source for the latest in Cybersecurity, AI, and Tech News.

Our website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.