At Salesforce, we understand that the confidentiality, integrity, and availability of your data is vital to your business. We want to inform our customers about a security incident involving the Drift app, published by Salesloft, that was installed by individual customers from AppExchange.
Salesforce security teams detected unusual activity that may have resulted in unauthorized access to a small number of customers' org data via the Drift app's connection to Salesforce. This issue did not stem from a vulnerability within the core Salesforce platform, but rather from a compromise of the Drift app's connection credentials.
Upon detecting the activity, Salesloft (in collaboration with Salesforce) invalidated active Access and Refresh Tokens and removed Drift from AppExchange. On August 28, 2025 at 04:09 AM UTC, Salesforce disabled the connection between the Drift application and Salesforce.
Update 1 — Thursday, August 28, 2025 at 7:23 PM UTC: Salesforce disabled all integrations between Salesforce and all Salesloft technologies, including the Drift app. Organizations are not able to connect to Salesforce via any Salesloft apps until further notice.
Update 2 — Sunday, September 7, 2025 at 5:30 PM UTC: Salesforce has re-enabled integrations with Salesloft technologies, with the exception of the Drift app. Drift will remain disabled until further notice, following security measures and remediation steps implemented by Salesloft and independently validated by Mandiant.
For Salesloft's latest investigation and remediation updates, see the latest here.
Helpful Resources
Helpful Articles
Salesforce Trust Post - Unusual Activity in a Third Party Connected App
Mandiant Blog - Widespread Data Theft Targets Salesforce Instances via Salesloft Drift
Salesforce has completed initial remediation steps in response to this security incident. As of September 7, 2025, integrations with Salesloft technologies are re-enabled — the Drift app remains the only exception and will stay disabled until further notice.
Recommended actions to protect your Salesforce org:
For Salesloft's latest investigation and remediation updates, refer to the Salesloft Trust page (see Additional Resources).
005134951

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.