All Posts
October 8, 2026
5 min read
700 Companies Were Breached by a Chatbot Nobody Owned
Stolen tokens from Drift's chatbot gave attackers access to more than 700 Salesforce tenants, and no security tool caught it. The seams let them in, but weeks of scoping did the damage.
Table of contents
Overview

700 Companies Were Breached by a Chatbot Nobody Owned

March 2025. Attackers get into Salesloft's GitHub environment. Over the following months they work their way into Drift's AWS environment and take the OAuth and refresh tokens belonging to Drift, an AI chatbot wired into customers' Salesforce tenants. Then, for a while, nothing visible happens.

August 8–18, 2025. A threat actor Google tracks as UNC6395 uses them. Not to break in- to log in, as the application, into more than 700 Salesforce tenants. Cloudflare. Palo Alto Networks. Zscaler. Proofpoint. Systematic SOQL queries against Users, Accounts, Opportunities, Cases. Then the query jobs deleted behind them.

The target was never CRM records. It was what customers had pasted into support tickets over the years: AWS keys, Snowflake tokens, passwords. Cloudflare rotated 104 exposed API tokens.

November 2025. Same playbook, Gainsight-published Salesforce apps, 200+ instances.

June 2026. Same playbook again, through Klue. Entry point: a legacy credential from a 2022 pilot integration that was never deployed.

Ten months. Three campaigns. Zero zero-days.

Why every control missed

Walk it through the stack and watch each tool decline to see it.

The IdP saw nothing, because token replay isn't a login. No authentication event to challenge, no MFA to prompt, no conditional access to evaluate.

IGA certifies known human accounts from an HR feed, quarterly. A SaaS-to-SaaS grant made years earlier by whoever set up the chatbot was never in scope for a single campaign.

PAM protects credentials that were onboarded into it. This one lived in a vendor's infrastructure and in Salesforce's connected-app registry.

ITDR watches for technique. Here there was barely any- a trusted application making calls it was authorized to make, from a Tor exit node if you knew to look. Same behavior, different intent.

CNAPP governs IAM roles in AWS, Azure, GCP. The tokens were stolen from a vendor's AWS account and abused entirely inside SaaS- neither half was the customer's cloud.

Five categories of tooling and not one control point touched. Gartner named the IVIP category in 2025 for the gap this exposes, and the diagnosis is right: the attack lived in the seams.

But we'd argue the seams weren't the expensive part.

{{large-cta}}

The expensive part was the week after

When Drift broke, every Drift-connected Salesforce customer faced the same question under a regulatory clock: which third-party applications hold tokens into our environment, what can each one reach, and which were touched?

Many needed weeks, and no single party held the whole record.

That's the number that decided how badly this hurt each company. Not detection speed- scoping speed. Legal exposure, customer notifications and disclosure deadlines all ran while teams reconstructed an integration inventory by hand.

So here's a bar worth setting for your own program. From a cold start, how long until you can list every non-human identity that can reach your crown-jewel data, what each one's scopes are, and what it touched last week?

If that's measured in weeks, that's your real exposure- and unlike the breach itself, it's a number you control.

The three properties that make it a query instead of a project

Reach. The exposure concentrates in the applications nobody onboarded: the homegrown tool, the legacy system with no API, the integration procured on a credit card. If governance scope is the twenty tiles in your SSO tenant, the risk is by definition outside it. Coverage that arrives in eighteen months is coverage of an environment that no longer exists- which is why we built ConnectAny to reach any source in days, and why connecting one gives you findings in hours with no rules to write.

Evidence over registry. A pilot integration that was never deployed appears in no HR feed, no registry, no request ticket. It exists only as signal- a grant, a log line, a config entry. Governance that starts from a declared list inherits every gap in the list. Building identities bottom-up from raw evidence is how Oak shows customers identities they didn't know they had- the ones that exist only as a grant or a log line, outside every list they were governing from.

Action. A perfect map of every OAuth grant, delivered as a dashboard, would not have prevented any of these three campaigns. One CISO we work with had a leading graph product and said it plainly: beautiful dashboards, nothing they could do with them. Revoking a risky grant fixes today; tracing it to the provisioning policy that created it stops it coming back next quarter.

Nobody was watching the application, because nobody had ever decided the application was an identity.

That decision is the whole job.

‍

AI agents made identity wilder than ever. Are you prepared?

Map and manage your agentic identities, their owners, and their access in one place.

GET A DEMO

Discover related posts