Supply Chain Attacks in the SaaS Era: Unpacking the Drift Breach | Cloudflare x The CISO Signal
It was just a little chat window in the corner of the screen. But behind it was a web of trusted connections reaching deep inside the enterprise. Here’s how attackers turned a trusted integration into a massive supply chain breach. 👇 Expand for more details and resources 👇
In August 2025, attackers tracked as UNC6395 compromised OAuth tokens associated with Salesloft’s Drift integration. This turned trusted connections to Salesforce environments into an attack path reaching hundreds of companies, including top-tier cybersecurity organizations.
In this episode of The CISO Signal | True Cybercrime Podcast, host Jeremy Ladner and Volker Rath (Field CISO APAC at Cloudflare) investigate the Drift breach. They break down how attackers compromise trust upstream, what they were looking for inside stolen Salesforce data, and why your attack surface no longer ends at the edge of your network.
⏱️ Chapters:
0:00 - The Chat Widget That Hacked the Enterprise
2:15 - Breakdown of the Drift & Salesloft Breach (August 2025)
8:30 - How UNC6395 Exploited Salesforce OAuth Tokens
15:45 - The Downstream Blast Radius of Trusted Integrations
22:10 - Detecting Malicious Behavior in Legitimate Access
31:00 - Rethinking Third-Party Risk & Zero Trust
42:20 - How AI Accelerates SaaS Supply Chain Attacks
🔍 In this episode, we explore:
- How compromised OAuth tokens create massive downstream vulnerabilities.
- Why traditional third-party risk programs fail to measure inherited trust.
- The limits of token revocation during incident response.
- New assumptions CISOs must make about authorized connections.