Skip to content

ScopeMantle is SOC 2 Type II in progress, read our trust commitments →

Breach Pattern

The Salesloft Drift Breakdown: The first supply-chain OAuth breach of this decade

How a chat-widget vendor's stolen tokens became hundreds of compromised CRMs, and the policy that would have caught it.

The incident that named the pattern

August 2024 is when a lot of CISOs learned that a website chat widget could empty a CRM. Drift, acquired by Salesloft, stored Salesforce OAuth refresh tokens so transcripts could land on leads without another login. Attackers got into Salesloft's GitHub environment, took those tokens, and replayed them against Salesforce APIs. Public reporting described hundreds of customer CRM instances hit. Salesforce passwords were not the story. A marketing tool people had forgotten still held a valid delegate credential.

Defenders watching Salesforce logins and IP reputation saw noise that looked like the integration working. Refresh traffic came from Drift's expected infrastructure. Blast radius was the scopes someone approved years earlier, often read and write on contacts, opportunities, and notes.

A ScopeMantle tenant would have listed those grants continuously, raised severity when Salesloft disclosed, and offered bulk revoke for every employee who ever clicked Connect. Eighteen months later, boards still say "Drift" when they mean AI extensions. Many orgs ran one connected-app audit in late 2024 and never looked again. Campaign season reconnects the same class of tool.

This is a mechanics and control write-up. It is not a customer case study. We were not in those tenants. We do not invent victim counts beyond what public reporting already said.

Timeline (public reporting, condensed)

Before 2024. Marketing and RevOps put Drift on the site. AEs connect it to Salesforce so chat can qualify leads. Each connect creates a refresh token in Salesloft's multi-tenant backend. Security blessed Salesforce in procurement. Drift often never entered the vendor register. It was "just a widget."

August 2024, day 0. Salesloft finds unauthorized access to a GitHub repo in Drift's CI/CD path. Attackers collect OAuth client material and refresh tokens. Containment starts. Customers are not all notified yet because token-theft scope is still being scoped.

Days 2 to 3. Tokens replay against customer Salesforce orgs. Exfil focuses on contacts, opportunities, and email metadata: fraud and spear-phish fuel. Salesforce teams see API anomalies. Attribution to Drift is not instant.

Day 5. Criminal forums list CRM exports tied to Drift OAuth client IDs. Salesforce publishes guidance to revoke connected apps tied to Drift. Customers try to find which production and sandbox orgs authorized it. Spreadsheet audits take days.

Day 7 and after. Confirmed victims climb into the hundreds in public write-ups. CISA and analysts treat supply-chain OAuth as its own TTP. Vendors rename modules. Few ship identity-layer grant inventory. Marketing quietly reconnects a chat tool in Q4 unless someone blocked the client ID.

2025 to 2026. Snowflake connectors and Context.ai get cited next to Drift in root-cause notes. Privacy teams get asked for processor lists that omit the widget because the RoPA predates the install.

Attack mechanics

Salesforce OAuth here is authorization-code with offline access. Drift's servers trade codes for refresh tokens and store them. Encryption at rest does not help once attackers have application secrets and datastore access. Replay uses Salesforce's real token endpoint. IP allowlists rarely block Drift ranges because those IPs are supposed to call Salesforce.

Scopes accumulate. A 2021 authorize screen is not a 2024 feature set. Users often never saw a re-consent. Attackers inherit the superset. "Read-only" in a UI still means export-scale API access in practice.

Multi-tenant vault, many customers. Same shape as Context.ai holding Google refresh tokens. Downstream API changes. Trust-boundary failure does not. Horizontal scale is the attacker's advantage. Per-customer IR is the tax you pay if you cannot revoke by client ID in one motion.

SIEM content still loves impossible travel and VPN weirdness. It does not love refresh velocity from a martech ASN. CASBs on a forward proxy never see vendor-to-Salesforce TLS. Salesforce Event Monitoring can catch replay volume after the fact. That is detective, after inventory already failed.

What you can do without ScopeMantle

  1. In Salesforce, export Connected Apps for production and every sandbox. Keep consumer key / client ID, not just the label.
  2. In Google Admin and Okta, search for the same vendor names and any SSO grants that point at CRM tools.
  3. Build a client-ID emergency list for chat, intent, and conversation-intelligence tools. Store it where IR can find it on a Friday.
  4. Revoke first, then tell marketing. If you reverse that order during an active replay, you will lose the weekend.
  5. Export Connected Apps again after revoke. That before/after pair is CC9.2 terminate-access evidence.
  6. Put an OAuth re-attestation gate on the campaign calendar. Black Friday reconnects without review recreated 2024 for more than one retailer, in public post-mortems of the class.
  7. If contacts and opportunities are personal data in your counsel's view (they usually are), start processor notification in parallel. Use operator templates from the DSAR playbook, counsel-adapted.

What ScopeMantle would have shown

Breach History. Disclosure matches known Drift / Salesloft client IDs. Critical. Auto-revoke if you enabled that policy.

Scope Sanity. A chat widget asking for CRM object write scores badly (we use "under 35" as the illustrative band for this category miss). New installs queue. Stale ones show up on the board slide.

Owner mapping. RevOps and marketing ops titles. After emergency revoke, those humans are who reconnect unless you block the client ID and talk to revenue leadership.

Cross-IdP. Many firms reach Salesforce through Google Workspace SSO. Okta and Google connectors surface grants when CRM admin consoles are split by business unit or agency.

We do not sit on Salesforce APIs. If your only grant path never touches Google or Okta, we will not invent visibility. Entra bulk revoke is Beta.

Lessons that still fail in 2026

  • Martech is infosec. If it OAuths into CRM, MAP, or a warehouse, it is a CC9.2 vendor.
  • One-time connected-app audits die within a quarter.
  • Revoke playbooks name client IDs. Brands lie after M&A.
  • Finance stopping payment does not revoke a token. Tie SaaS offboarding to grant removal (deprovisioning model).
  • Threat-intel feeds that mention vendor names are slower than a client-ID match in your own inventory.

What to tell an auditor (post-incident or tabletop)

"Here is the Connected Apps export from day 5 and day 6. Here is the IdP grant export. Here is the revoke timestamp. Here is the campaign-calendar control so reconnect requires attestation." Do not claim ScopeMantle was deployed if it was not. Do not claim HIPAA. Do not invent how many of "our customers" were in the Drift victim set. We do not publish that.

IR hour-by-hour if this happens again

  1. Hour 0. Confirm the vendor name and collect every client ID / consumer key you have ever seen for that brand and its acquirer. Search sandboxes and agency orgs.
  2. Hour 1. Revoke those IDs in Salesforce Connected Apps and in the IdP. Do not wait for a perfect comms draft.
  3. Hour 2. Export before/after. Start a running list of which business units just lost a workflow (chat-to-lead, conversation intelligence).
  4. Hour 4. Privacy: if contacts left the tenant, counsel decides notice. Security does not freelance a blog post.
  5. Hour 24. Campaign and web teams get a written "do not reconnect" and an approved alternative if you have one.
  6. Day 7. Re-export. Anyone who reconnected is either an exception with a sponsor or a policy failure.

Threat-intel subscriptions help when you do not yet have inventory. They are slower than a client-ID match in a tenant you already sync. Pair them. Do not pick a religion.

What not to say on the incident call

  • "Salesforce was hacked." Usually false and it burns a partner you still need.
  • "We do not use Drift." Check client IDs and historical Connected Apps, including deleted-looking labels.
  • "CASB would have caught it." Vendor-to-Salesforce TLS says hello.
  • "We are HIPAA covered through our GRC tool." Irrelevant and, for ScopeMantle, untrue. We are not attested.

What to do this week

  1. Export Salesforce Connected Apps and IdP OAuth grants. Highlight chat and conversation tools.
  2. Write the Friday 16:00 tabletop: vendor discloses, you must revoke a client ID before Monday open. Time it.
  3. Add a campaign-calendar checkpoint: no reconnect without security review.
  4. Read Context.ai, Snowflake connectors, and the playbook.
  5. Trial if you want the IdP side on a daily sync. $5 annual / $6 monthly, no seat min, custom 500+.

Sandbox, agency, and renamed modules

Production revoke is necessary and not sufficient. Sandboxes copy connected apps. Agencies authorize from their own users. Salesloft and Drift branding moved around after acquisition. Your search terms should include former names, parent names, and the consumer key if you ever stored it. A display-name filter is how you miss the sandbox that still syncs contacts to a forgotten widget.

After revoke, conversation-intelligence and chat-to-lead workflows break. That is the point. Have a written fallback (native web-to-lead, approved vendor) so revenue does not reconstruct the grant at 22:00 from a personal admin account. Personal admin accounts in Salesforce are their own CC6.7 problem. Mention them in the IR notes if you find them.

CRM data classification drives the privacy fork. Contacts and opportunities usually contain personal data. Internal notes sometimes contain everything you promised never to put in a ticket. Processor notification is counsel's call. Your job is the inventory snapshot that proves who could have seen it.

Salesforce Event Monitoring can show replay volume after the fact. Treat it as detective, not as a substitute for knowing the Connected Apps list on Friday afternoon. Threat-intel feeds that mention vendor names are slower than a client-ID match in a tenant you already export. Pair them. After the incident week, put an OAuth re-attestation checkpoint on the campaign calendar so Q4 does not silently rebuild the same grant.

Field guide: Connected Apps plus IdP the same afternoon

Salesforce export for production and sandboxes. Google and Okta search for chat and conversation tools. Agency orgs if you have them. Revoke, then comms, unless counsel says stealth for a few hours. Before/after exports are the CC9.2 packet. Campaign calendar checkpoint the same week, while people still remember why.

We do not connect to Salesforce APIs. IdP inventory is the slice. $5 / $6, no seat min. Context.ai for the extension flavor.

Search former names, parent names, and consumer keys. Sandboxes and agencies are where people miss. Event Monitoring is detective. Inventory is the Friday control. We still do not sit on Salesforce APIs. Price stays public. Entra stays Beta. No invented victim overlap with our design partners.

If you only remember one operational sentence: revoke the consumer key and the IdP client ID, then prove it with a second export. Brands lie after acquisitions. IDs do not. Campaign season will try to reconnect the cousin. Put a human on that calendar.

Re-export Connected Apps a week later. Anyone who reconnected needs a sponsor or they are a policy failure. That is the end of the incident week and the start of the program.

FAQ

Common questions

About ScopeMantle

ScopeMantle is an OAuth-grant audit and DSAR-automation platform for mid-market SaaS companies, sold primarily through an open MSSP partner program (70/30 wholesale split, deal registration, no direct-sale conflict in partner territories) and secondarily direct. Built in 2026.

Explore the partner program →

70 / 30 wholesale · deal registration honoured · no direct-sale conflict

Find the Context.ai in your org before the attacker does.

15-minute connection. First inventory in an hour. Vendor risk scores for every third party by tomorrow.

Book a demo to see the inventory on your own tenant.