What happened
Threat actors harvest active OAuth tokens from a compromised chat integration server and run automated API scripts to drain Salesforce directories.
2025-08-15
CriticalPrimaryAnalysis of the August 2025 Salesloft Drift AI breach where stolen OAuth tokens from a chat agent integration were used to exfiltrate Salesforce CRM data.
What happened
Threat actors harvest active OAuth tokens from a compromised chat integration server and run automated API scripts to drain Salesforce directories.
Why it matters
Mass exfiltration of sensitive CRM data, including enterprise customer records, pricing sheets, and sales pipeline histories.
Missing authorization check
Not applicable: no agent authorization boundary was crossed in this incident.
Would PP block it?
The compromise ran through package, credential, or vendor infrastructure rather than through an agent tool call, so there is no agent action for an authorization gate to hold.
Incident analysis
2025-08-15
Salesforce security teams isolate anomalous CRM API bulk exfiltration patterns originating from Drift integration IPs.
2025-08-18
Salesloft publishes urgent security bulletin advising all customers to revoke and rotate Drift Salesforce OAuth permissions.
Authorization boundary
This incident is categorized as Credential exposure. The relevant Permission Protocol gate is Credential Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
No agent took an action in this incident. Permission Protocol gates what an agent does, so it does not apply where the harm required no agent action.
Start small
This incident maps to Credential Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.