A year ago this month, the Salesloft/Drift OAuth supply chain attack changed how we look at third-party app integrations.

When Salesloft disclosed a security issue in their Drift application in late August 2025, it initially looked like just another vendor breach.[1] But in September, Google Threat Intelligence noticed something worse: it wasn’t just Salesforce data. The attackers took valid OAuth tokens for hundreds of services customers had integrated with Salesloft, including Slack, Amazon S3, Microsoft Azure, and OpenAI.[1]

Three months later in November 2025, the same threat actors used those stolen Drift OAuth tokens to pivot straight into Gainsight’s infrastructure.[2] From there, they reached into the Salesforce environments of 200 different Gainsight customers with the exact same playbook.[2]

The SaaS Basement

We used to think of OAuth as a read/write convenience so users didn’t have to share passwords. But Drift and Gainsight showed us that OAuth integrations are really untethered, long-lived credentials sitting quietly in the SaaS basement. They are service accounts masquerading as user features.

When someone clicks “Allow” to connect a chatbot to their CRM, they mint a token. If stolen, that token grants persistent access to whatever scopes were requested. Because these tokens live outside the usual identity boundaries, they skip right past your conditional access rules, MFA challenges, and most anomaly detection.

What Has Changed?

The questions to ask haven’t changed over the last year, but you actually need to answer them now.

Have you audited your Entra ID enterprise applications recently? Do you know exactly which third-party apps hold active refresh tokens into your Salesforce instance or your Azure environment?

If your SOC only watches human logins and ignores machine-to-machine OAuth tokens, you’re missing half the picture. We should treat them like Domain Admin credentials: trim the scopes, lock down the service principals, and watch the API logs for abuse.

If you haven’t reviewed the connected apps in your environment since the Drift fallout, you’re just waiting for the next one.

Sources

[1] https://krebsonsecurity.com/2025/09/the-ongoing-fallout-from-a-breach-at-ai-chatbot-maker-salesloft [2] https://www.apexhours.com/salesforce-data-breaches-what-really-went-wrong-and-how-to-protect-your-org