Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2025-08-15

CriticalPrimary

Stolen OAuth Tokens From Salesloft Drift AI Chat Integration Used to Mass-Export Salesforce CRM Data Across Hundreds of Orgs

Analysis of the August 2025 Salesloft Drift AI breach where stolen OAuth tokens from a chat agent integration were used to exfiltrate Salesforce CRM data.

Drift AI Chat AgentCredential exposureOAuth Token Hijacking and Lateral ExfiltrationThird-party AI chat integration pipeline

What happened

Threat actors harvest active OAuth tokens from a compromised chat integration server and run automated API scripts to drain Salesforce directories.

Why it matters

Mass exfiltration of sensitive CRM data, including enterprise customer records, pricing sheets, and sales pipeline histories.

Missing authorization check

Not applicable: no agent authorization boundary was crossed in this incident.

Would PP block it?

The compromise ran through package, credential, or vendor infrastructure rather than through an agent tool call, so there is no agent action for an authorization gate to hold.

Incident analysis

Timeline and technical read

Timeline

  1. 2025-08-15

    Salesforce security teams isolate anomalous CRM API bulk exfiltration patterns originating from Drift integration IPs.

  2. 2025-08-18

    Salesloft publishes urgent security bulletin advising all customers to revoke and rotate Drift Salesforce OAuth permissions.

Technical breakdown

  • Attackers identified a database vulnerability in the shared Drift chat integration pipeline, gaining access to raw, unencrypted OAuth credentials.
  • The threat actor parsed the token database and fanned out automated curl scripts across multiple rotating residential proxies, bypassing standard IP-based rate controls to pull Salesforce directories.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Credential exposure. The relevant Permission Protocol gate is Credential Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Credential Gate, Salesforce API integration proxy
Still needs
PP does not prevent the initial compromise of the central Salesloft/Drift integration database.
Receipt required for
Exporting bulk CRM contacts, reading database records above a velocity threshold, or accessing sensitive API tokens

No agent took an action in this incident. Permission Protocol gates what an agent does, so it does not apply where the harm required no agent action.

Start small

Put the relevant gate at this action boundary.

This incident maps to Credential Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop