Full Report
On 2025-08-21, an incident was reported, involving UNC6395, gaining initial access via Unknown, to achieve Supply chain attack.
Analysis Summary
# Incident Report: UNC6395 Supply Chain Compromise via Salesloft Drift
## Executive Summary
On August 21, 2025, threat group UNC6395 successfully executed a supply chain attack, leveraging an unknown initial access vector targeting the Salesloft Drift platform. The incident resulted in a compromise impacting downstream customers via the compromised software supply chain, leading to potential data theft from Salesforce instances connected to the platform.
## Incident Details
- Discovery Date: August 21, 2025 (Based on public report date)
- Incident Date: On or before August 21, 2025
- Affected Organization: Salesloft/Drift (Indirectly, via compromise of their integration/software)
- Sector: Software/Technology (SaaS), impacting downstream users connected to Salesloft Drift.
- Geography: Not specified, assumed to affect global users of the platform.
## Timeline of Events
### Initial Access
- **Date/Time:** Unknown, prior to the public report date of 2025-08-21.
- **Vector:** Unknown.
- **Details:** UNC6395 gained initial access related to the Salesloft Drift platform, subsequently exploiting this access for a supply chain attack.
### Lateral Movement
- Details are not provided in the context, but the nature of the compromise suggests movement within the Salesloft/Drift environment or its dependencies to facilitate payload delivery or data staging.
### Data Exfiltration/Impact
- **Impact:** Supply chain attack leading to potential data theft from Salesforce instances connected to the compromised platform.
### Detection & Response
- **Detection:** An incident was reported publicly on August 21, 2025.
- **Response Actions:** Not detailed in the provided summary context.
## Attack Methodology
*Note: Since the source context is limited, the MITRE ATT&CK mappings below are inferred based on the description of a "Supply chain attack" leading to "data theft from Salesforce instances."*
- **Initial Access:** Unknown.
- **Persistence:** Unknown.
- **Privilege Escalation:** Unknown.
- **Defense Evasion:** Unknown.
- **Credential Access:** Likely via the supply chain exploitation mechanism used to access connected Salesforce data.
- **Discovery:** Unknown.
- **Lateral Movement:** Assumed movement to compromise the delivery mechanism or directly access connected customer data stores.
- **Collection:** Data collection targeting information stored within connected Salesforce instances.
- **Exfiltration:** Data theft from connected Salesforce instances.
- **Impact:** Compromise of downstream customer data integrity and confidentiality via a compromised vendor.
## Impact Assessment
- **Financial:** Not specified.
- **Data Breach:** Potential theft of sensitive data from connected Salesforce instances.
- **Operational:** Disruption/loss of trust in the Salesloft Drift platform and connected integrations.
- **Reputational:** Negative impact on Salesloft and Drift trust levels.
## Indicators of Compromise
- **Network indicators:** None provided.
- **File indicators:** None provided.
- **Behavioral indicators:** None provided.
## Response Actions
- **Containment measures:** Not specified.
- **Eradication steps:** Not specified.
- **Recovery actions:** Not specified.
## Lessons Learned
- The incident highlights the severe risks inherent in the software supply chain, where compromise of a single vendor impacts numerous downstream clients.
- The initial access vector remains a critical gap requiring further investigation.
## Recommendations
- Immediate forensic review of the Salesloft/Drift environment to determine the precise initial access vector exploited by UNC6395.
- Implement enhanced auditing and monitoring for data access patterns originating from third-party integrations accessing sensitive data stores (e.g., Salesforce).
- Review vendor risk management programs focusing on security posture validation for critical SaaS dependencies like Salesloft Drift.