Recommended Free Tools
Yes—but Google said the impact was limited to a very small number of Workspace accounts specifically configured to use Salesloft Drift Email. The access occurred on August 9, 2025, through compromised Drift OAuth tokens. Google said other accounts in the same Workspace domains were not reachable through this incident and that neither Google Workspace nor Alphabet itself was compromised.
What happened to Google Workspace accounts?
Google Threat Intelligence Group said that on August 9, 2025, an attacker used tokens associated with the Salesloft Drift third-party application to access email from a very small number of Google Workspace accounts. The potentially affected accounts were those configured to integrate with Drift Email. Google said accounts in the same domains without that integration were not reachable through this event.
This was access through a trusted third-party integration, not a breach of Google’s Workspace service or Alphabet’s systems. Google’s August 28, 2025 update said: “To be clear, there has been no compromise of Google Workspace or Alphabet itself.”
How the Drift campaign unfolded
Google tracked the attacker as UNC6395. Google said the broader campaign began as early as August 8, 2025, and continued through at least August 18, using compromised OAuth tokens associated with the Salesloft Drift application to access Salesforce instances.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Salesloft’s Mandiant-backed investigation found earlier access to a Salesloft GitHub account from March through June 2025, followed by access to Drift’s AWS environment and acquisition of customer-integration OAuth tokens. Those tokens enabled the attacker to act through integrations that customers had authorized.
Salesforce said the issue arose from compromised Drift connection credentials, not a vulnerability in Salesforce’s core platform. In its customer advisory, Salesforce stated: “This issue did not stem from a vulnerability within the core Salesforce platform, but rather from a compromise of the Drift app’s connection credentials.”
Rank #2
- HARDWARE 2FA AND MFA: FIDO Alliance Certified FIDO2 v2.1 with CTAP2 plus legacy U2F and CTAP1 for strong two-factor login and passwordless sign-in on services that support security keys
- BUILDING ACCESS ON ONE CARD: MIFARE DESFire EV2 4K applet with AES encryption adds office door and physical access control alongside digital authentication
- CERTIFIED SECURE ELEMENT: An NXP Common Criteria EAL6+ certified secure controller and Java Card platform protects your keys on a tamper-resistant chip
- DUAL INTERFACE SMART CARD: Contactless NFC ISO 14443 plus ISO 7816 contact reader support in an ISO 7810 ID-1 format that is passive and needs no battery
- SWISS ENGINEERED DESIGN: Built by Cryptnox as a single card for authentication and access control and backed by a 2 year warranty
What information did UNC6395 target?
Google reported that the actor systematically exported large volumes of Salesforce data, including records from Accounts, Users, Opportunities and Cases. The actor then searched those exports for credentials and other secrets, including AWS access keys beginning with AKIA, passwords, Snowflake-related access tokens, VPN and SSO URLs, and similar sensitive strings. Google also observed the deletion of query jobs while logs remained available for investigation.
Finding sensitive data in an export is not the same as proving that every matching credential was used. Organizations should treat exposed secrets as at risk until they have checked and rotated them, and should investigate logs for possible follow-on access.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- Universal Connectivity (USB-C & NFC): The Thetis PRO-A features integrated USB Type C and NFC for a near-instant account unlock. Simply unfold the key and hold it to your smartphone’s NFC antenna to authenticate on the go.
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.
FINRA reported in 2025 that the wider breach affected more than 700 organizations. It said exposed information commonly included names, titles, email addresses, phone numbers, and Salesforce data such as Accounts, Contacts, Opportunities and Cases. FINRA also described access through Salesforce, Google Workspace and, in some cases, Slack integrations. That organization count is not a count of Google Workspace accounts.
How exposure differed by integration
| Configuration or data | What the public statements establish | What it means for an organization |
|---|---|---|
| Drift Email integration configured for a Workspace account | Google said email access occurred on August 9, 2025, in a very small number of such accounts. | Review the account’s integration and audit history, and assess email and credentials available to that connection. |
| No Drift Email integration on a Workspace account | Google said other accounts in the same Workspace domains were not reachable through this event. | The stated Workspace email exposure was tied to the configured integration, not every account in a customer domain. |
| Salesforce connected to Drift | Google described Salesforce exports; Salesforce attributed the incident to Drift connection credentials rather than a core Salesforce vulnerability. | Review the connected app, exported records and activity logs; assess secrets stored in Salesforce data. |
| Other connected services, including Slack | FINRA said some cases involved Slack integrations, but the public statements summarized here do not specify a complete list of affected integrations or per-service counts. | Inventory every Drift connection and investigate each service according to its own logs and authorization scope. |
Google has not published a precise count of affected Workspace accounts; its public description is “a very small number.” The public statements cited here also do not provide a single financial-loss total.
Rank #4
- FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
- Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
- USB TYPE A Connectivity & DONGLE Design: Designed for PCs, Macs, laptops and Android devices that utilize a USB-A port. Plug and stay, or carry it on a keychain. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
- Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
- Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC functionality is not supported.
What affected organizations should do
- Inventory Drift connections. Identify every third-party integration connected to Drift, including whether Drift Email and Salesforce connections were enabled, which accounts or records they could access, and whether other services were linked.
- Revoke and rotate credentials. Revoke or rotate Drift OAuth tokens, API keys and other credentials in scope. Reset associated user passwords and replace any secrets that may have appeared in integrated data, including cloud, Snowflake, VPN and SSO credentials.
- Review audit logs for the incident window. Examine Google Workspace, Salesforce and other connected-system logs for unusual access from August 8 through August 18, 2025. In Salesforce, review Event Monitoring, Connected App authentication and UniqueQuery events, as recommended in the incident guidance.
- Search exported records and support data for secrets. Look for strings such as
AKIA, “Snowflake,” “password,” “secret,” and VPN or SSO URLs. Use an appropriate secret-scanning tool where available, and investigate matches rather than assuming every match was accessed or exploited. - Reduce integration access. Apply least privilege, restrict connected-app scopes and IP ranges where supported, and remove unnecessary API access. Recheck whether each integration still needs the permissions it holds.
- Use Salesforce’s connected-app guidance. Review OAuth Usage, revoke or rotate tokens as appropriate, and monitor the Salesforce Trust page for relevant service and security updates.
Keep a record of which integrations and credentials have been checked, which tokens have been revoked or rotated, and which log reviews remain open. This helps distinguish completed containment from work still pending.
Quick Recap
Best Value
- 【Replacement Doorbell Key】: As a small accessory of the doorbell, security pin keys may be easily lost, so our doorbell key tool can be used as your card pin replacement
- 【Valued Packaging】: There are two types of doorbell opening pin tool in our package, release tool removal pins are suitable for different doorbells. Included 2 x flat head pins, 2 x pointed pins and a key ring
- 【Compatible Models】: Flat head pins of replacement doorbell keys are compatible with Blink doorbell and Google nest doorbell, and pointed pins are compatible with Arlo, Blink, Google Nest and Eufy Video Doorbell, TP-Link Tapo Smart Video Doorbell D210/D130/D230S1
- 【Easy to Grip】: The design of the security key tool is different from ordinary card pins. Doorbell opening tool has a solid handle, which is easy to grasp and saves effort when using it. Compatible with blink doorbell key
- 【Convenient for Storage】: Doorbell removal opening key comes with a key ring, you can choose to take one of the card pins separately, and put the rest in the drawer for later use, which is convenient for storage and not easy to lose
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

