SaaS integrations often stay connected long after the original rollout, supplier project or CRM upgrade has finished. Many senior leadership teams only revisit those permissions once suspicious activity forces an investigation and customer confidence has already started taking a hit.
The Salesloft Drift breach exposed how attackers can abuse trusted cloud access without breaking into Salesforce itself. Instead, attackers used compromised OAuth tokens, which work like digital permission keys, to access Salesforce customer instances through Drift integrations that businesses already trusted operationally.
SMEs using Salesforce and connected sales platforms may have far more linked apps and OAuth permissions than they realise. New integrations spread across systems quickly while review processes slowly fall behind, which is exactly why CASB tools are becoming more important for businesses trying to keep control of cloud access.
Businesses can struggle to review old integrations, supplier permissions and OAuth access once SaaS environments start expanding across multiple systems. We help organisations regain visibility before those gaps turn into customer complaints, investigation delays or wider operational disruption.
What happened in the Salesloft Drift breach?
Google Threat Intelligence Group linked the incident to a threat actor known as UNC6395. Activity connected to the breach took place during August 2025.
Drift is a sales and customer-chat platform owned by Salesloft. Businesses often connect Drift directly to Salesforce during CRM upgrades or customer-service rollouts so sales staff can manage lead activity and customer conversations from one place.
Attackers did not break into Salesforce itself. Instead, they used compromised OAuth tokens linked to Drift integrations.
OAuth tokens work like digital permission keys. Once approved, connected apps can continue accessing parts of cloud systems without repeated sign-ins.
According to Google Threat Intelligence Group, attackers accessed Salesforce customer instances through those compromised Drift OAuth tokens and exported data from objects including:
- accounts
- users
- cases
- opportunities
Google also reported that attackers searched the stolen data for:
- passwords
- AWS keys
- Snowflake-related tokens
Salesloft and Salesforce later revoked active Drift access and refresh tokens while investigations continued. Salesforce also removed Drift from the AppExchange marketplace.
Google later advised organisations to review third-party integrations connected to Drift, revoke and rotate credentials, and investigate connected systems for signs of unauthorised access.
The Drift incident mattered because attackers used access businesses had already approved internally. Businesses often keep relying on the same integrations for years without revisiting how much access those systems still hold.
Why do connected SaaS apps become security risks over time?
SaaS integrations usually stay connected long after the original rollout, supplier project or CRM upgrade has finished.
A reporting platform added during a migration may still hold access years later. An old supplier account may still connect into the CRM because nobody wanted to interrupt dashboards or automations people still rely on.
Most businesses only start reviewing those permissions once suspicious activity forces an investigation.
By that stage, customer-support staff may already be handling account concerns while IT investigates which systems attackers accessed first and how far permissions still spread across the environment.
The Drift incident mattered because attackers used trusted app access businesses had already approved internally instead of directly attacking Salesforce itself.
A short no-obligation TrustLayer demo can help you review which integrations still hold access across CRM and cloud systems before suspicious activity turns into a wider investigation.
How does CASB help businesses control connected cloud apps?
Businesses often lose track of which apps still connect into CRM systems, cloud storage and browser-based sales platforms once SaaS environments start expanding across multiple suppliers and integrations.
CASB helps businesses review linked cloud apps, risky OAuth permissions and suspicious SaaS activity from one place instead of manually tracing access across disconnected platforms during investigations.
That becomes particularly useful once reporting tools, CRM add-ons and supplier-managed integrations all connect into the same environment.
Old integrations often remain active long after businesses stop using them properly. Some apps also accumulate broader access over time as new automations, reporting tools and workflows get added.
TrustLayer CASB supports businesses in finding forgotten integrations, review risky cloud permissions and investigate suspicious SaaS activity before customer complaints or operational disruption start escalating.
If you relly on CRM integrations, browser-based sales platforms or linked cloud tools, a TrustLayer demo can help review where older integrations, supplier access or unnecessary permissions may already be creating operational risk.
What practical CASB steps should SMEs take next?
SaaS environments usually become harder to manage gradually during CRM upgrades, supplier onboarding and periods of fast growth.
Start by reviewing every linked app currently connected to systems such as Salesforce, Microsoft 365 or shared cloud storage.
Unused integrations should be removed completely.
OAuth permissions also need regular review. Some integrations quietly accumulate broader access as new automations, reporting features and workflows get added over time.
Exposed credentials should be rotated regularly. Multi-factor authentication should remain enabled across connected cloud platforms. Supplier access also needs consistent review once projects, migrations or onboarding work finishes.
Cloud environments often expand faster than internal review processes can keep up. Once suspicious activity appears, organisations may no longer fully understand:
- which apps still hold access
- where sensitive data flows
- which integrations remain active
- how attackers may have moved through connected systems
Regular CASB reviews can help reduce investigation delays, identify forgotten integrations earlier and improve visibility across linked cloud systems before customer concerns start escalating.
Why does the Salesloft Drift breach matter beyond Salesforce?
The Drift incident showed how trusted SaaS integrations can quietly become access routes into customer data, CRM systems and cloud platforms without directly compromising Salesforce itself.
As SaaS environments expand across suppliers, reporting tools and browser-based sales platforms, older integrations and OAuth permissions can remain active far longer than expected.
That is exactly where CASB becomes valuable. It gives organisations clearer visibility into linked cloud apps, risky permissions and suspicious activity before investigations become harder to manage.
If your business already relies on Salesforce integrations or connected cloud tools, a short no-obligation TrustLayer demo can help review where older integrations, supplier access or unnecessary permissions may already be creating operational risk.
You can also contact the TrustLayer team to discuss CASB support, SaaS visibility and cloud-access oversight in more detail.