Between August 8 and 18, 2025, a threat actor tracked as UNC6395 used OAuth tokens stolen from Salesloft’s Drift AI chatbot integration to systematically query and export data from more than 700 organizations’ Salesforce environments, including Cloudflare, Google, Palo Alto Networks, Proofpoint, Zscaler, and PagerDuty. The stolen data was largely confined to Salesforce support-case text, contacts, and account information, though attackers also harvested authentication tokens for other connected services, including OpenAI API credentials. Investigators later traced the initial compromise to Salesloft’s GitHub repositories, which had been accessed by the attackers since March 2025.