On-Demand Videos & Webinars

Detecting the Salesloft Drift Attack: From Stolen OAuth Token to Gong Exfiltration

Detecting Salesloft Drift activity comes down to catching a trusted integration behaving like an attacker.

In this Mitiga Minutes episode, Mitiga Principal Solutions Engineer Steve Schohn walks through the auto-generated incident view for the compromise pattern that hit hundreds of organizations' Salesforce instances in 2025. The Drift connected-app token authenticates to Salesforce from a new source, and Mitiga attributes the event to the application itself, a non-human identity operating on a compromised employee account. An AI triage summary argues both hypotheses and lands on the only one the evidence supports, since there is no sign-in correlation and no interactive login from the IP. The view then follows the lateral movement from Salesforce into Gong, where call recordings and transcripts are exported in bulk in a single session. No analyst assembled the timeline, and the same panoramic visibility covers the rest of the cloud estate.

Watch the episode above, with host Brian Contos, Mitiga Field CISO. New Mitiga Minutes episodes land regularly here and on the Mitiga YouTube channel.

‍

Related from Mitiga

Don't miss these stories