Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Palo Alto Networks Salesforce Data Theft 2025: A…
Breach analysis Incident: 2 Sep 2025

Palo Alto Networks Salesforce Data Theft 2025: A Victim’s View of the Salesloft Drift OAuth Token Attack

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 7 min read
Category: NHI
On this page

On 2 September 2025, Palo Alto Networks confirmed it was one of hundreds of organisations whose Salesforce data was stolen through the Salesloft Drift supply chain attack. Drift, an AI chat application from Salesloft, connected to customers' Salesforce environments with OAuth tokens. The threat group Google tracks as UNC6395 used stolen Drift tokens to query and export Salesforce data from its victims. At Palo Alto Networks, the attacker "extracted primarily business contact and related account information, along with internal sales account records and basic case data," the company said. It disconnected Drift, investigated through its Unit 42 team and said no products, systems or services were affected. The concern for customers was what they had typed into support cases: a spokesperson told CyberScoop that "a small number of customers who included sensitive information, such as credentials, in their recent case notes might also have had that data compromised." Palo Alto Networks said it was contacting those customers directly. This page covers the victim's side; the campaign itself is on our Salesloft Drift breach page.

Key takeaways

  • Attackers used OAuth tokens stolen from the Salesloft Drift integration to export data from Palo Alto Networks' Salesforce CRM.
  • Stolen data was mostly business contact details, sales account records and basic support case data, the company said.
  • Some customers had put credentials in support case notes, and those may have been exposed.
  • Palo Alto Networks said its products, systems and services were not affected, disconnected Drift and revoked the associated tokens.
  • The identity lesson: a third-party app's OAuth token is a standing key to your data, and support tickets often hold other people's secrets.

At a glance

OrganisationsPalo Alto Networks; Salesloft (Drift application); Salesforce (platform)
WhenSalesloft Drift campaign disclosed late August 2025; Palo Alto Networks confirmed its exposure on 2 September 2025
AttackerUNC6395, as tracked by Google's Threat Intelligence Group
Entry pointStolen OAuth tokens for the Salesloft Drift integration with Salesforce; how they were first obtained was unconfirmed at the time
Identities abusedDrift's OAuth access to Palo Alto Networks' Salesforce instance; credentials some customers left in support case notes
ImpactBusiness contact, sales account and basic support case data exported; possible exposure of customer credentials in case notes; no product impact
CategoryNHI. Incident class: confirmed NHI breach (stolen third-party OAuth tokens used to export CRM data)

What happened

BleepingComputer heard about the breach over the weekend of 30 and 31 August from Palo Alto Networks customers, who were worried that information they had shared in support cases, such as IT details and passwords, had been exposed. The company then confirmed: "Palo Alto Networks confirms that it was one of hundreds of customers impacted by the widespread supply chain attack targeting the Salesloft Drift application that exposed Salesforce data." It added: "We quickly contained the incident and disabled the application from our Salesforce environment. Our Unit 42 investigation confirms that this situation did not affect any Palo Alto Networks products, systems, or services."

According to BleepingComputer, Palo Alto Networks said the exfiltrated support case data contained contact information and text comments, not technical support files or attachments. In its own blog, the company said it was "reaching out to a limited number of customers that have potentially more sensitive data exposed." It also revoked the associated tokens and rotated credentials.

Palo Alto Networks' Unit 42 threat brief, quoted by BleepingComputer, described what the attacker did with the data: "Following exfiltration, the actor appeared to be actively scanning the acquired data for credentials, likely with the intent to facilitate further attacks or expand their access." The searches looked for AWS access keys, Snowflake tokens, VPN and SSO login strings and words such as "password," "secret" or "key." The attackers deleted query jobs to hide their activity and used Tor, BleepingComputer reported. How UNC6395 first obtained the Drift tokens was still unconfirmed at the time, CyberScoop noted.

Timeline

DateEvent
Late August 2025The Salesloft Drift supply chain attack on Salesforce customers is disclosed.
30 August 2025Over that weekend, Palo Alto Networks customers raise concerns with BleepingComputer.
2 September 2025Palo Alto Networks confirms the breach and publishes an incident response blog.

How it happened: the identity attack path

  1. Third-party token stolen. The attacker obtained OAuth tokens for the Drift integration, by a route not confirmed at the time.
  2. Trusted access used. The tokens let the attacker query Palo Alto Networks' Salesforce as the Drift application.
  3. Bulk export. Account, contact, case and opportunity records were exported.
  4. Secret hunting. The attacker scanned the data for credentials that could open other systems.
  5. Containment. Palo Alto Networks disconnected Drift, revoked tokens and rotated credentials.

Impact

  • Stolen: business contact information, internal sales account records and basic support case data.
  • At risk: credentials that some customers had written into recent support case notes.
  • Not affected: Palo Alto Networks products, systems and services, according to the company.

What this means for NHI governance

The victim's view of this attack is a lesson in inherited risk. Palo Alto Networks did nothing unusual: it connected a chat tool to its CRM, as hundreds of companies did. That connection was an OAuth grant, a non-human identity with standing access to Salesforce data, whose credentials were held by a third party. When the third party lost them, every connected CRM was open.

There is a second lesson in what was inside the CRM. Support cases collect secrets: customers paste passwords, API keys and configuration to get help. The attacker searched for exactly those. Governing SaaS integrations means inventorying OAuth grants, scoping them tightly and monitoring their use; governing support data means detecting and redacting secrets on arrival. See our SaaS and OAuth App Governance Guide and Third-Party Access Guide.

Recommendations

  • Inventory and scope third-party OAuth grants. Know which apps can read your CRM and limit them to what they need. See the SaaS and OAuth App Governance Guide.
  • Monitor integration activity. Alert on bulk exports and unusual queries by connected apps. See the ITDR Guide.
  • Redact secrets from support systems. Scan tickets and case notes for credentials and remove them.
  • Rotate secrets shared in support cases. Customers of any affected vendor should treat credentials they shared as exposed. See the Leaked Credential Response Playbook.
  • Plan for vendor compromise. Be able to disconnect and revoke an integration quickly. See the Third-Party Access Guide.

Frequently asked questions

Was Palo Alto Networks breached?

Its Salesforce CRM data was stolen through the Salesloft Drift supply chain attack. Palo Alto Networks says its products, systems and services were not affected.

What Palo Alto Networks data was exposed?

Mostly business contact information, internal sales account records and basic support case data. Some customers who put credentials in recent case notes may have had those exposed.

What should Palo Alto Networks customers do?

Rotate any credentials shared in support cases, and review access for any system whose secrets may have been included in case notes.

Salesloft Drift Breach 2025 · BeyondTrust Breach 2024 · SaaS and OAuth App Governance Guide · Third-Party Access Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Third-party OAuth grants are among the most overlooked non-human identities. We help teams find them, scope them and prepare to revoke them the moment a vendor is compromised. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org