Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

There is no public, tenant-by-tenant answer to whether a particular company’s records were accessed in the Salesloft Drift incident. Public reporting confirms a campaign against Salesforce and other Drift-connected services, but the oft-cited figure of more than 700 organizations is a campaign-wide organization count—not a record count and not proof that every Drift customer was compromised.

Your organization needs its own connected-application records, audit logs, vendor notifications and credential review to determine exposure.

What happened in the Drift-linked intrusion?

Google Threat Intelligence Group attributed the activity to UNC6395. In an advisory published August 26, 2025 and updated August 28, Google said the actor used stolen OAuth credentials associated with the Salesloft Drift application to enter customer Salesforce instances from August 8 through at least August 18, 2025. The actor queried Salesforce objects, exported data and searched the results for secrets. Google observed searches for AWS access keys, passwords and Snowflake-related access tokens.

Google reported that the actor deleted query jobs, but not the underlying logs. Its account of the campaign says, “The actor systematically exported large volumes of data from numerous corporate Salesforce instances.” Read the dated Google Threat Intelligence Group and Mandiant advisory for the original timeline and indicators.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Salesforce says the incident involved compromised Drift connection credentials rather than a vulnerability in the core Salesforce platform. Salesforce invalidated active Drift access and refresh tokens and removed Drift from AppExchange, according to its security response article.

Which integrations and accounts entered the reported scope?

The initial reporting centered on Drift’s Salesforce connection. Google’s August 28 update expanded the warning: the incident was not exclusive to Salesforce, and Drift customers should treat authentication tokens stored in or connected to Drift as potentially compromised.

Salesforce OAuth

The actor accessed customer Salesforce instances through Drift-associated OAuth tokens. Reported queries included Cases, Accounts, Users and Opportunities. Exported case text is important because support records can contain credentials that were never intended to be stored in a CRM.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Drift Email and Google Workspace

Google confirmed OAuth-token access to email on August 9 in a very small number of Google Workspace accounts that were specifically configured for Drift Email. Google said other Workspace accounts on those customers’ domains were not accessible through this mechanism, and that Google Workspace and Alphabet themselves were not compromised. The advisory does not give an exact account count.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Other connected services

FINRA reported that some organizations also had Salesforce, Google Workspace and Slack integrations in the affected scope. The exact path depended on which Drift connections a company enabled and what credentials or secrets were placed in connected systems.

What data may have been exposed?

FINRA’s alert says, “The scope of the compromised data varied by organization but commonly included business contact records including names, titles, emails and phone numbers, as well as Salesforce objects like Accounts, Contacts, Opportunities and Cases.” Those are common categories, not a list of data taken from every organization.

Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

In some support cases, FINRA found more sensitive material, including API keys, Snowflake tokens, cloud credentials or passwords. A company should therefore inspect case text and other communications, not just CRM fields. The FINRA cybersecurity alert is the source for the organization count, data categories and response recommendations.

What does “more than 700 organizations” actually mean?

FINRA reported that the campaign affected more than 700 organizations. That figure is a count of organizations associated with the campaign, reported by FINRA in 2026. It is not a count of records, people, Salesforce objects or confirmed data-loss events. It also cannot show whether any particular tenant’s records were read or exported.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Impact can differ sharply between two Drift customers: one may have used only a limited Salesforce connection, while another may have enabled Drift Email, Slack or other integrations and stored credentials in support cases. Only tenant-specific evidence can resolve that difference.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display

How to determine whether your organization was affected

  1. Identify every Drift connection. Inventory Drift-to-Salesforce OAuth, Drift Email or Workspace OAuth, Slack and any other OAuth or customer-managed API-key integration active during August 8–18, 2025.
  2. Preserve and review audit evidence. Examine Salesforce connected-app and API logs, Google Workspace audit logs, Slack logs where applicable, token-use records, source IPs and unusual export or query activity during the window. Google said query jobs may have been deleted, so do not treat missing jobs as proof that no access occurred.
  3. Check vendor notifications and forensic findings. Compare your tenant identifiers, integration type and observed indicators with notices from Drift, Salesloft, Salesforce and other affected service providers. A campaign-wide count cannot substitute for a notification or investigation about your environment.
  4. Inspect records that could contain secrets. Search support cases, notes, messages and attachments for API keys, passwords, cloud credentials and Snowflake tokens. Revoke or replace anything that may have been exposed.
  5. Document the determination. Record the connection involved, time range reviewed, queries and exports found, credentials rotated, and any evidence that the tenant was not accessed. This creates an auditable basis for customer, legal and regulatory decisions.

Response actions recommended by the published alerts

Revoke, rotate and disconnect

  • Disconnect relevant Salesloft or Drift integrations with Salesforce, Google Workspace, Slack and other platforms while investigating.
  • Rotate potentially exposed OAuth tokens, refresh tokens, API keys, passwords, cloud credentials and Snowflake credentials.
  • Apply least privilege when reconnecting integrations; grant only the objects, mailboxes and actions the workflow requires.

Review logs and downstream systems

  • Review Salesforce, Workspace and Slack audit logs for August 8–18, 2025, focusing on unusual exports, bulk reads, token use and unfamiliar IP addresses.
  • Use Salesforce’s Connected Apps OAuth Usage view and access logs as part of the review; these steps are included in Salesforce’s response guidance.
  • Investigate any downstream account that used a secret found in a case or other Drift-connected record.

Prepare for follow-on abuse

  • Monitor for phishing and social engineering aimed at employees or customers whose business contact details may have been exposed.
  • Warn help-desk and sales teams that an attacker may use accurate names, titles or case details to make follow-up messages credible.
  • Escalate suspected misuse, credential abuse or regulatory impact through your incident-response process.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are Drift and its integrations available now?

Availability statements need a date because the vendors published successive status changes. Salesforce’s article, published May 4, 2026, reproduces a September 7, 2025 update saying Salesloft integrations had been re-enabled except Drift, which remained disabled at that point.

The Salesloft/Clari Trust Center says Drift was brought back online September 16, 2025, with third-party integrations restored progressively. The same page also contains later notices about Drift being temporarily offline, hardening work and subsequent restoration. These records do not provide a single, synchronized present-day matrix for every integration. Check the current Trust Center notice and your own integration settings before making an operational availability claim.

How to read the evidence by connection type

Connection type Potential data at risk Evidence to review Immediate response
Drift-to-Salesforce OAuth Accounts, Contacts, Opportunities, Cases, Users and case text Connected-app OAuth usage, API and export logs, query activity and source IPs Revoke or rotate tokens, disconnect while investigating, inspect records for embedded secrets
Drift Email / Workspace OAuth Email in specifically integrated Google Workspace accounts Workspace audit logs, mailbox access, OAuth token use and the exact integrated accounts Revoke tokens, review affected mailboxes and rotate credentials found in messages
Other OAuth integrations, including Slack Data permitted by that integration and any secrets stored there Service-specific audit logs, token records and vendor indicators Disconnect or revoke the connection, then investigate the permitted data scope
Customer-managed API keys Systems and data reachable with the key, including cloud or Snowflake resources Key-use logs, authentication events and records where the key appeared Disable and replace keys, then review downstream access

What the public record does not establish

  • It does not establish a total number of records taken.
  • It does not show that every one of the more than 700 organizations lost every listed data type.
  • It does not provide an exact count of Google Workspace accounts accessed through Drift Email.
  • It does not give a universal current status for every Drift integration.
  • It does not determine whether your company was affected without tenant-specific logs, notifications or forensic analysis.

What Mandiant reported about the related Salesloft environment

The Trust Center hosts a Mandiant investigation summary covering an engagement that began August 26, 2025 and concluded September 30, 2025. The summary’s findings are accurate as of that conclusion date. It describes suspicious activity from March 22 through September 5, including TOR and anonymizing-proxy API calls, use of Salesloft GitHub personal access tokens for reconnaissance and secret enumeration, and exfiltration of environment-variable secrets and code repositories. Mandiant said it did not identify ongoing compromise of Drift, verified remediation activities and verified technical separation between Drift and Salesloft environments.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Those dated findings describe the vendor investigation; they do not replace a review of your organization’s own integrations and logs.

The Bottom Line

The Drift campaign’s blast radius remains unresolved at the individual-company level. Treat the reported organization count as a warning signal, then determine your exposure from the integrations you used, the records and secrets they contained, audit evidence for August 8–18, 2025, and the vendors’ tenant-specific findings.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.