ShinyHunters Claims Theft of 1.5 Billion Salesforce Records via Drift OAuth Tokens
CriticalWhat happened
The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies by exploiting compromised Salesloft Drift OAuth tokens. The attackers allegedly breached Salesloft's GitHub repository, extracted OAuth tokens, and used them to access and exfiltrate data from Salesforce instances.
Who is affected
Approximately 760 companies utilizing Salesforce, including major firms like Google, Cloudflare, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, JFrog, Nutanix, Qualys, Rubrik, Cato Networks, and Palo Alto Networks, are reportedly impacted.
Why it matters
The breach exposes sensitive customer and business data, increasing the risk of further cyberattacks, identity theft, and corporate espionage. The scale and method of the attack highlight vulnerabilities in third-party integrations and the importance of securing OAuth tokens.
How it could have been prevented
Implementing strict access controls and regular audits of third-party integrations, securing and rotating OAuth tokens, and conducting thorough code reviews to detect and remove hardcoded secrets could have mitigated the risk.
Relevant professional terms
- OAuth Token
- A secure authorization token that allows third-party applications to access user data without exposing credentials.
- Extortion Group
- A cybercriminal organization that steals data or disrupts services to demand ransom from victims.
Recommended reading: Salesloft: March GitHub repo breach led to Salesforce data theft attacks
