{"id":27986,"date":"2025-09-05T05:50:54","date_gmt":"2025-09-05T05:50:54","guid":{"rendered":"https:\/\/www.adminbyrequest.com\/?p=27986"},"modified":"2026-01-24T22:45:46","modified_gmt":"2026-01-24T22:45:46","slug":"salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft","status":"publish","type":"post","link":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft","title":{"rendered":"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft"},"content":{"rendered":"\n<p>Between August 8 and 18, threat actors successfully compromised the Salesloft Drift AI chat platform, using stolen OAuth tokens to systematically pillage data from hundreds of corporate Salesforce instances. This supply chain attack has become one of the most significant breaches of 2025.<\/p>\n\n\n\n<p>Google Threat Intelligence Group (GTIG) <a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/data-theft-salesforce-instances-via-salesloft-drift\" target=\"_blank\" rel=\"noopener\" title=\"\">tracked the campaign<\/a> to a previously unknown threat actor designated UNC6395, who demonstrated remarkable operational discipline while conducting what security researchers are calling a widespread credential harvesting operation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How the Attack Unfolded<\/h2>\n\n\n\n<p>The breach began when attackers gained access to Salesloft&#8217;s Drift platform, a popular AI-powered chat agent used for sales automation and customer engagement. UNC6395 systematically exported large volumes of data from numerous corporate Salesforce instances, with GTIG assessing that the primary intent was to harvest credentials.<\/p>\n\n\n\n<p>This attack was highly methodical. Not content with simple data theft, the threat actors actively mined the stolen information for high-value credentials including Amazon Web Services (AWS) access keys, passwords, and Snowflake-related access tokens.<\/p>\n\n\n\n<p>The attackers demonstrated sophisticated operational security by deleting query jobs to cover their tracks, though fortunately for investigators, the underlying audit logs remained intact.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-1-1-1024x576.png\" alt=\"\" class=\"wp-image-27981\" srcset=\"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-1-1-1024x576.png 1024w, https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-1-1-300x169.png 300w, https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-1-1-768x432.png 768w, https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-1-1-1536x864.png 1536w, https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-1-1-800x450.png 800w, https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-1-1.png 1820w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Scale of the Damage<\/h2>\n\n\n\n<p>The attack <a href=\"https:\/\/thehackernews.com\/2025\/08\/salesloft-oauth-breach-via-drift-ai.html\" target=\"_blank\" rel=\"noopener\" title=\"\">affected over 700 organizations<\/a>, specifically targeting companies using the Drift-Salesforce integration. Several major companies have publicly confirmed they were impacted, including cybersecurity firms Zscaler and Palo Alto Networks.<\/p>\n\n\n\n<p>Google&#8217;s investigation later revealed that the scope of this compromise extended beyond just the Salesforce integration to impact other integrations as well. The attack also compromised OAuth tokens for Drift&#8217;s email integration, giving attackers access to a small number of Google Workspace accounts.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Data Was Stolen<\/h2>\n\n\n\n<p>The attackers targeted specific Salesforce objects that would yield the most valuable information. They executed queries to retrieve data from:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>User accounts and contact information<\/li>\n\n\n\n<li>Support cases containing potentially sensitive technical details<\/li>\n\n\n\n<li>Account and opportunity records<\/li>\n\n\n\n<li>Business contact details and licensing information<\/li>\n<\/ul>\n\n\n\n<p>Perhaps most concerning was the attackers&#8217; focus on support cases, which often contain technical details, error messages, and sometimes even credentials shared by customers seeking assistance.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Broader AI Agent Security Problem<\/h2>\n\n\n\n<p>This attack exposes the growing security risks that come with AI agent platforms requiring extensive integrations and elevated privileges to function.<\/p>\n\n\n\n<p>Traditional software applications typically operate with limited, defined permissions. AI agents need access to email, CRM platforms, databases, and other business-critical applications to be truly useful. This creates an attractive target for attackers who can potentially gain access to an organization&#8217;s entire digital ecosystem through a single compromised agent.<\/p>\n\n\n\n<p>AI agents inherit many of the security risks outlined in the <a href=\"https:\/\/genai.owasp.org\/llm-top-10\/\" target=\"_blank\" rel=\"noopener\" title=\"\">OWASP Top 10 for LLMs<\/a>, such as prompt injection, sensitive data leakage and supply chain vulnerabilities. However, their integration with external tools exposes organizations to classic software threats like credential theft and broken access control.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-2-1-1024x576.png\" alt=\"\" class=\"wp-image-27982\" srcset=\"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-2-1-1024x576.png 1024w, https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-2-1-300x169.png 300w, https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-2-1-768x432.png 768w, https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-2-1-1536x864.png 1536w, https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-2-1-800x450.png 800w, https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/inline-2-1.png 1820w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Response and Recovery Efforts<\/h2>\n\n\n\n<p>The response was swift once the breach was discovered. On August 20, 2025, Salesloft and Salesforce worked together to revoke all active access and refresh tokens associated with the Drift application. Salesforce also removed Drift from its AppExchange marketplace pending further investigation.<\/p>\n\n\n\n<p>All impacted customers were notified directly, and organizations were advised to:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Search their Salesforce instances for sensitive information and credentials<\/li>\n\n\n\n<li>Rotate any discovered API keys and passwords<\/li>\n\n\n\n<li>Review authentication logs for suspicious activity<\/li>\n\n\n\n<li>Implement stronger IP restrictions and access controls<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Lessons for IT Security Teams<\/h2>\n\n\n\n<p>This breach offers several critical lessons for organizations deploying AI agents and third-party integrations:<\/p>\n\n\n\n<p><strong>Audit Your AI Agent Permissions<\/strong>: Review what access your AI platforms have and <a href=\"\/en\/blogs\/how-to-implement-the-principle-of-least-privilege-in-your-organization\" target=\"_blank\" rel=\"noopener\" title=\"\">whether they truly need such broad privileges<\/a>. Many organizations discover their AI tools have far more access than necessary for their actual use cases.<\/p>\n\n\n\n<p><strong>Implement Zero Trust for AI Integrations<\/strong>: Don&#8217;t assume AI platforms are inherently trustworthy. Apply the same security controls you would to any third-party application, including network segmentation and continuous monitoring.<\/p>\n\n\n\n<p><strong>Monitor OAuth Token Usage<\/strong>: The attack succeeded because stolen OAuth tokens provided legitimate-looking access to Salesforce instances. Organizations need better visibility into how their authentication tokens are being used, particularly by automated systems.<\/p>\n\n\n\n<p><strong>Plan for Supply Chain Compromises<\/strong>: Incident response plans need to account for scenarios where <a href=\"\/en\/blogs\/pam-vs-vpam-why-vendor-access-deserves-special-attention\" target=\"_blank\" rel=\"noopener\" title=\"\">threats come through trusted third-party vendors<\/a> rather than direct attacks on your infrastructure.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What&#8217;s Next<\/h2>\n\n\n\n<p>AI agents often demand access to email, CRM systems, and databases, but this creates massive attack surfaces that most organizations haven&#8217;t properly considered. When Salesloft Drift got compromised, attackers inherited trusted relationships with hundreds of customer Salesforce instances.<\/p>\n\n\n\n<p>The rush to deploy AI solutions for productivity gains has left many companies overlooking basic security fundamentals. Every OAuth token, API connection, and elevated permission becomes a potential pathway for attackers to move laterally through corporate systems.<\/p>\n\n\n\n<p>The security community needs practical frameworks for evaluating AI agent risks before these platforms become even more entrenched in business operations. Organizations should implement granular permission models and stronger oversight to limit damage when things inevitably go wrong.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors used stolen OAuth tokens to breach Salesforce data at scale, exposing major flaws in AI agent integrations and enterprise security.<\/p>\n","protected":false},"author":16,"featured_media":27989,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[36],"tags":[44,83,148,223,448],"ppma_author":[428],"class_list":["post-27986","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blogs","tag-ai","tag-cyber-attack","tag-cybersecurity","tag-data-breach","tag-news","entry","has-media"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 4.9.5.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"Threat actors used stolen OAuth tokens to breach Salesforce data at scale, exposing major flaws in AI agent integrations and enterprise security.\" \/>\n\t<meta name=\"robots\" content=\"max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n\t<meta name=\"author\" content=\"Pocholo Legaspi\"\/>\n\t<meta name=\"keywords\" content=\"ai,cyber attack,cybersecurity,data breach,news\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 4.9.5.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Admin By Request \u00bb Local Admin Rights, Managed.\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft\" \/>\n\t\t<meta property=\"og:description\" content=\"Threat actors used stolen OAuth tokens to breach Salesforce data at scale, exposing major flaws in AI agent integrations and enterprise security.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2023\/05\/Circle-Tick-24.svg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2023\/05\/Circle-Tick-24.svg\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-09-05T05:50:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-01-24T22:45:46+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/adminbyrequest\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@AdminByRequest\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Threat actors used stolen OAuth tokens to breach Salesforce data at scale, exposing major flaws in AI agent integrations and enterprise security.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@AdminByRequest\" \/>\n\t\t<meta name=\"twitter:image\" content=\"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2023\/05\/Circle-Tick-24.svg\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#blogposting\",\"name\":\"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft\",\"headline\":\"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft\",\"author\":{\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/author\\\/pocholo-editor#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/main-2.png\",\"width\":1820,\"height\":1024},\"datePublished\":\"2025-09-05T05:50:54+00:00\",\"dateModified\":\"2026-01-24T22:45:46+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#webpage\"},\"articleSection\":\"Blogs, AI, Cyber Attack, Cybersecurity, Data Breach, News, Pocholo Legaspi\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/category\\\/blogs#listItem\",\"name\":\"Blogs\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/category\\\/blogs#listItem\",\"position\":2,\"name\":\"Blogs\",\"item\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/category\\\/blogs\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#listItem\",\"name\":\"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#listItem\",\"position\":3,\"name\":\"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/category\\\/blogs#listItem\",\"name\":\"Blogs\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/#organization\",\"name\":\"Admin By Request\",\"description\":\"Local Admin Rights, Managed.\",\"url\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/\",\"telephone\":\"+12622994600\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"\\\/wp-content\\\/uploads\\\/2023\\\/05\\\/Circle-Tick-24.svg\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft\\\/#organizationLogo\"},\"sameAs\":[\"https:\\\/\\\/www.facebook.com\\\/adminbyrequest\",\"https:\\\/\\\/twitter.com\\\/AdminByRequest\",\"https:\\\/\\\/www.instagram.com\\\/AdminByRequest\\\/\",\"https:\\\/\\\/www.tiktok.com\\\/@adminbyrequest\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UCwq1wlbT9m_z3YH-EPaZqKw\",\"https:\\\/\\\/www.linkedin.com\\\/company\\\/adminbyrequest\\\/\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/author\\\/pocholo-editor#author\",\"url\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/author\\\/pocholo-editor\",\"name\":\"Pocholo Legaspi\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#webpage\",\"url\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft\",\"name\":\"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft\",\"description\":\"Threat actors used stolen OAuth tokens to breach Salesforce data at scale, exposing major flaws in AI agent integrations and enterprise security.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/author\\\/pocholo-editor#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/author\\\/pocholo-editor#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/wp-content\\\/uploads\\\/2025\\\/09\\\/main-2.png\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft\\\/#mainImage\",\"width\":1820,\"height\":1024},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/blogs\\\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#mainImage\"},\"datePublished\":\"2025-09-05T05:50:54+00:00\",\"dateModified\":\"2026-01-24T22:45:46+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/\",\"name\":\"Admin By Request\",\"alternateName\":\"ABR\",\"description\":\"Local Admin Rights, Managed.\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.adminbyrequest.com\\\/en\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<script type=\"text\/javascript\">\n\t\t\t(function(c,l,a,r,i,t,y){\n\t\t\tc[a]=c[a]||function(){(c[a].q=c[a].q||[]).push(arguments)};t=l.createElement(r);t.async=1;\n\t\t\tt.src=\"https:\/\/www.clarity.ms\/tag\/\"+i+\"?ref=aioseo\";y=l.getElementsByTagName(r)[0];y.parentNode.insertBefore(t,y);\n\t\t})(window, document, \"clarity\", \"script\", \"n4woz8og40\");\n\t\t<\/script>\n\t\t<script>(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https:\/\/www.googletagmanager.com\/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer',\"GTM-PGQ6572W\");<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft<\/title>\n\n","aioseo_head_json":{"title":"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft","description":"Threat actors used stolen OAuth tokens to breach Salesforce data at scale, exposing major flaws in AI agent integrations and enterprise security.","canonical_url":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft","robots":"max-snippet:-1, max-image-preview:large, max-video-preview:-1","keywords":"ai,cyber attack,cybersecurity,data breach,news","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#blogposting","name":"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft","headline":"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft","author":{"@id":"https:\/\/www.adminbyrequest.com\/en\/author\/pocholo-editor#author"},"publisher":{"@id":"https:\/\/www.adminbyrequest.com\/en\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/main-2.png","width":1820,"height":1024},"datePublished":"2025-09-05T05:50:54+00:00","dateModified":"2026-01-24T22:45:46+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#webpage"},"isPartOf":{"@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#webpage"},"articleSection":"Blogs, AI, Cyber Attack, Cybersecurity, Data Breach, News, Pocholo Legaspi"},{"@type":"BreadcrumbList","@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.adminbyrequest.com\/en#listItem","position":1,"name":"Home","item":"https:\/\/www.adminbyrequest.com\/en","nextItem":{"@type":"ListItem","@id":"https:\/\/www.adminbyrequest.com\/en\/category\/blogs#listItem","name":"Blogs"}},{"@type":"ListItem","@id":"https:\/\/www.adminbyrequest.com\/en\/category\/blogs#listItem","position":2,"name":"Blogs","item":"https:\/\/www.adminbyrequest.com\/en\/category\/blogs","nextItem":{"@type":"ListItem","@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#listItem","name":"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.adminbyrequest.com\/en#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#listItem","position":3,"name":"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft","previousItem":{"@type":"ListItem","@id":"https:\/\/www.adminbyrequest.com\/en\/category\/blogs#listItem","name":"Blogs"}}]},{"@type":"Organization","@id":"https:\/\/www.adminbyrequest.com\/en\/#organization","name":"Admin By Request","description":"Local Admin Rights, Managed.","url":"https:\/\/www.adminbyrequest.com\/en\/","telephone":"+12622994600","logo":{"@type":"ImageObject","url":"\/wp-content\/uploads\/2023\/05\/Circle-Tick-24.svg","@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft\/#organizationLogo"},"image":{"@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft\/#organizationLogo"},"sameAs":["https:\/\/www.facebook.com\/adminbyrequest","https:\/\/twitter.com\/AdminByRequest","https:\/\/www.instagram.com\/AdminByRequest\/","https:\/\/www.tiktok.com\/@adminbyrequest","https:\/\/www.youtube.com\/channel\/UCwq1wlbT9m_z3YH-EPaZqKw","https:\/\/www.linkedin.com\/company\/adminbyrequest\/"]},{"@type":"Person","@id":"https:\/\/www.adminbyrequest.com\/en\/author\/pocholo-editor#author","url":"https:\/\/www.adminbyrequest.com\/en\/author\/pocholo-editor","name":"Pocholo Legaspi"},{"@type":"WebPage","@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#webpage","url":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft","name":"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft","description":"Threat actors used stolen OAuth tokens to breach Salesforce data at scale, exposing major flaws in AI agent integrations and enterprise security.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.adminbyrequest.com\/en\/#website"},"breadcrumb":{"@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#breadcrumblist"},"author":{"@id":"https:\/\/www.adminbyrequest.com\/en\/author\/pocholo-editor#author"},"creator":{"@id":"https:\/\/www.adminbyrequest.com\/en\/author\/pocholo-editor#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/09\/main-2.png","@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft\/#mainImage","width":1820,"height":1024},"primaryImageOfPage":{"@id":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft#mainImage"},"datePublished":"2025-09-05T05:50:54+00:00","dateModified":"2026-01-24T22:45:46+00:00"},{"@type":"WebSite","@id":"https:\/\/www.adminbyrequest.com\/en\/#website","url":"https:\/\/www.adminbyrequest.com\/en\/","name":"Admin By Request","alternateName":"ABR","description":"Local Admin Rights, Managed.","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.adminbyrequest.com\/en\/#organization"}}]},"og:locale":"en_US","og:site_name":"Admin By Request \u00bb Local Admin Rights, Managed.","og:type":"article","og:title":"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft","og:description":"Threat actors used stolen OAuth tokens to breach Salesforce data at scale, exposing major flaws in AI agent integrations and enterprise security.","og:url":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft","og:image":"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2023\/05\/Circle-Tick-24.svg","og:image:secure_url":"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2023\/05\/Circle-Tick-24.svg","article:published_time":"2025-09-05T05:50:54+00:00","article:modified_time":"2026-01-24T22:45:46+00:00","article:publisher":"https:\/\/www.facebook.com\/adminbyrequest","twitter:card":"summary_large_image","twitter:site":"@AdminByRequest","twitter:title":"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft","twitter:description":"Threat actors used stolen OAuth tokens to breach Salesforce data at scale, exposing major flaws in AI agent integrations and enterprise security.","twitter:creator":"@AdminByRequest","twitter:image":"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2023\/05\/Circle-Tick-24.svg"},"aioseo_meta_data":{"post_id":"27986","title":"#post_title","description":"#post_excerpt","keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"seo_analyzer_scan_date":"2026-01-24 22:48:52","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"open_ai":null,"ai":{"faqs":[],"keyPoints":[],"titles":[],"descriptions":[],"socialPosts":{"email":[],"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2025-09-05 05:49:08","updated":"2026-01-24 22:48:52"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.adminbyrequest.com\/en\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/www.adminbyrequest.com\/en\/category\/blogs\" title=\"Blogs\">Blogs<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\tSalesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.adminbyrequest.com\/en"},{"label":"Blogs","link":"https:\/\/www.adminbyrequest.com\/en\/category\/blogs"},{"label":"Salesloft Drift AI Agent Vulnerability Leads to Widespread Data Theft","link":"https:\/\/www.adminbyrequest.com\/en\/blogs\/salesloft-drift-ai-agent-vulnerability-leads-to-widespread-data-theft"}],"authors":[{"term_id":428,"user_id":16,"is_guest":0,"slug":"pocholo-editor","display_name":"Pocholo Legaspi","avatar_url":{"url":"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/04\/Pocholo-Headshot.jpg","url2x":"https:\/\/www.adminbyrequest.com\/en\/wp-content\/uploads\/2025\/04\/Pocholo-Headshot.jpg"},"author_category":"1","user_url":"","last_name":"Legaspi","first_name":"Pocholo","job_title":"","description":"Pocholo Legaspi is a seasoned content marketer and SEO specialist with over nine years of experience crafting digital content that drives engagement and growth. With a background in tech and a Master\u2019s in Business Informatics, he brings a data-driven approach to content strategy and storytelling."}],"_links":{"self":[{"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/posts\/27986","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/users\/16"}],"replies":[{"embeddable":true,"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/comments?post=27986"}],"version-history":[{"count":2,"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/posts\/27986\/revisions"}],"predecessor-version":[{"id":27990,"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/posts\/27986\/revisions\/27990"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/media\/27989"}],"wp:attachment":[{"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/media?parent=27986"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/categories?post=27986"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/tags?post=27986"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www.adminbyrequest.com\/en\/wp-json\/wp\/v2\/ppma_author?post=27986"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}