The most damaging cloud breaches of 2025 did not require breaking into anyone’s network. Attackers stole or tricked their way into OAuth tokens, the digital permission slips that let one application act on your behalf inside another, and then used those tokens to pull data out of Salesforce, Google Workspace and Microsoft 365 through the front door. To the platform, it looked like a trusted integration doing its job.
This is a supply chain problem, not a software vulnerability. Every connector, plug-in and third-party app you authorize extends trust from your core systems to someone else’s code and credentials. When that vendor is compromised, or when an employee is persuaded to authorize a malicious app, the attacker inherits the trust. This article explains how these attacks work, what the August 2025 Salesloft Drift campaign revealed, and how to govern the integrations your business depends on.
How OAuth trust works, and how it breaks
OAuth is the standard behind every “Sign in with Google” button and every “Allow this app to access your Salesforce data” prompt. Instead of giving an app your password, you grant it a token with specific permissions, called scopes. A refresh token lets the app keep renewing that access, often for months, without asking again.
That design is convenient and generally safer than sharing passwords, but it creates three weaknesses attackers now exploit:
- Tokens bypass MFA. Multifactor authentication protects the login, not the token. A stolen token works without a password or second factor.
- Scopes are often too broad. Integrations frequently request full read access to an entire tenant when they need one object, and administrators approve it to get the project moving.
- Nobody watches them. Token activity from an approved app rarely triggers the alerts that a suspicious login from a new country would.
What the 2025 campaigns showed
Two campaigns against Salesforce customers in 2025 illustrate both routes in.
Tricking users into authorizing malicious apps. In June 2025, Google Threat Intelligence Group described a group it tracks as UNC6040 phoning employees while posing as IT support and talking them through authorizing a modified version of Salesforce’s Data Loader tool. Once connected, the attackers exported customer data in bulk and later used it for extortion. No vulnerability was involved; the users granted access themselves.
Stealing tokens from a trusted vendor. Between August 8 and 18, 2025, a group Google tracks as UNC6395 used OAuth tokens stolen from Salesloft’s Drift chat application to access the Salesforce instances of Drift’s customers. The attackers ran queries to size and export data, then searched it for secrets such as AWS access keys, Snowflake tokens and passwords that customers had left in support cases and records. A related Drift integration with Google Workspace was also abused for a small number of accounts. Well-known security companies, including Cloudflare, Zscaler and Palo Alto Networks, confirmed their Salesforce data was accessed.
On August 20, Salesloft and Salesforce revoked all active Drift tokens and Salesforce pulled the app from its AppExchange marketplace pending investigation. The lesson for every organization is uncomfortable: the victims did nothing wrong in the conventional sense. They had installed a popular, legitimate integration from a reputable vendor.
Why perimeter defenses miss it
Firewalls, endpoint agents and VPN logs never see SaaS-to-SaaS traffic. The connection runs from the vendor’s cloud to your SaaS provider’s cloud, authenticated with a valid token, using documented APIs. The only place the attack is visible is in the SaaS platform’s own audit and event logs, which many organizations either do not collect or do not review.
The data stolen also tends to be more valuable than it looks. CRM records and support tickets are full of contact details useful for phishing, and often contain credentials, API keys and internal URLs pasted in by staff or customers. The Drift attackers were explicitly hunting for those secrets to move from one breach to the next. Attackers such as the social engineering crews covered in Scattered Spider Isn’t Gone have shown how quickly a CRM foothold becomes a wider compromise.
Governing your SaaS trust chain
You cannot stop vendors from being breached, but you can limit what a stolen token can do and shorten how long it goes unnoticed:
- Inventory every connected app. List all OAuth grants and connected apps in Microsoft 365, Google Workspace, Salesforce and other core platforms, with an owner and business purpose for each. Remove anything unused.
- Restrict who can authorize apps. Require administrator approval for new third-party apps and block users from granting broad data scopes on their own. This alone would have stopped the Data Loader vishing technique.
- Apply least privilege to integrations. Limit scopes to the objects each integration needs, use dedicated integration users with narrow permissions, and restrict API access by IP range where the platform allows it.
- Monitor and revoke tokens. Collect SaaS audit logs, alert on unusual query volume or bulk exports by integration users, and have a tested procedure to revoke a vendor’s tokens within minutes.
- Keep secrets out of SaaS records. Scan CRM and ticketing data for passwords and keys, rotate anything found, and give support teams a secure way to exchange credentials.
- Adopt SaaS security posture management. SSPM tools continuously check configuration, connected apps and permissions across platforms, which is hard to do by hand once you have more than a few integrations.
- Add integrations to vendor risk reviews. Ask vendors how they store customer tokens, how quickly they notify you of compromise, and whether they support scoped, short-lived access.
The trade-off is speed of adoption. Admin approval and scope reviews slow down the teams that want a new tool today. That friction is small compared with an incident response across every system a compromised integration could reach. Our cybersecurity and compliance services include SaaS integration reviews and third-party risk assessments. For more on how stolen identities drive these breaches, see Credential and Identity Theft Is Reaching Crisis Levels.
Update (September 2026): The pattern continued after this article was first published. In November 2025, Salesforce revoked tokens for applications published by customer-success vendor Gainsight after detecting suspicious activity through those integrations, another case of a trusted connector becoming the path to customer data. Integration governance has become a standard item in audits and cyber insurance questionnaires.
Frequently asked questions
Does MFA protect against OAuth token theft?
Not directly. MFA protects the sign-in that creates a token, but once a token exists it can be used without a second factor. Token protection depends on narrow scopes, short lifetimes, IP restrictions and monitoring.
How do we find out which apps have access to our data?
Each major platform has an admin view of connected or enterprise applications and user consents: the Microsoft Entra admin center, the Google Workspace API controls page and Salesforce’s Connected Apps OAuth usage page. SSPM tools consolidate those views across platforms.
What should we do if a vendor we use reports a token compromise?
Revoke the integration’s tokens immediately, review audit logs for data access during the exposure window, rotate any credentials or keys stored in the affected platform, and assess whether notification obligations apply to the data involved.
Securing your integrations
Delana Technologies helps organizations map their SaaS integrations, cut excess permissions, set up monitoring for token misuse and build a response plan for vendor compromises. To review your SaaS trust chain, call 239.414.5126 or contact us.
Sources: Google Threat Intelligence Group, “Widespread Data Theft Targets Salesforce Instances via Salesloft Drift” (August 2025); Google Threat Intelligence Group reporting on UNC6040 voice phishing and Salesforce data theft (June 2025); public statements from Cloudflare, Zscaler and Palo Alto Networks on the Drift incident (September 2025); Salesforce security advisory on Gainsight-published applications (November 2025).
