Hackers Exploit OAuth Tokens, Target 700 Salesforce Clients in Major Breach
Cybersecurity Dive
|
Contributed by: Kate Gamble
Summary
Hackers targeting Salesforce customers have stolen user credentials via compromised OAuth tokens from Salesloft's Drift AI chat agent, affecting over 700 organizations. The attacks, executed between August 8 and 18, primarily aimed to harvest sensitive credentials such as AWS access keys and Snowflake tokens, without exploiting vulnerabilities in Salesforce itself. In response, Salesforce and Salesloft have acted to revoke access tokens and urged administrators to reauthenticate connections. This incident highlights significant security risks associated with third-party integrations in healthcare technology, emphasizing the need for enhanced vigilance and security protocols among healthcare professionals.