The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Engineering & DevTools/Threat Talks
Threat Talks artwork

Inside the SalesLoft Breach

Threat Talks · 2025-11-18 · 22 min

0:00--:--

Topics in this episode

Zero TrustCyber SecurityHackON2IT

Episode notes

You were promised safe SaaS - but got silent data loss. In Inside the Salesloft Breach, Rob Maas and Luca Cipriano expose how trusted integrations became the attack vector. They trace how vishing calls, trojanized Salesforce tools, and GitHub-to-AWS pivots gave attackers OAuth access and drained CRMs without a single alert. You’ll hear how Drift integrations and bulk SOQL queries quietly moved data out of sight, while audit trails and API metadata disappeared. If you need provable control over data exfiltration and a narrative your board will understand, this is your playbook. Turn Zero Trust from slogan to stop - with IP allowlists, app inventories, token telemetry, and shared responsibility that actually blocks abuse at the source. (00:00) - Cloud first did not mean data safe. (00:45) - What Salesforce is and why attackers target it. (02:00) - Campaign one. Vishing and a trojanized data loader to OAuth access. (04:15) - Campaign two. Salesloft and Drift path from GitHub to AWS to Salesforce tokens. (07:00) - Impact and cover up. 700 plus orgs hit and API job metadata removed. (09:10) - Who was involved. ShinyHunters, Scattered Spider, Lapsus, and legal fallout.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • 93. Stop Wasting Payroll: How A $2,500 AI Automation Creates $80K in RevenueUnHacked · on Cyber Security88 / 100
  • The Weakest Link in a Global Life Sciences Company? People. With Dr. Kevin JonesCyber Leaders · on Zero Trust88 / 100
  • AI Security: Patricia Titus on Shadow AI, Non-Human Identities, and AI DefenseAI Security, Cyber Risk, and Cloud Strategy on ClearTech Loop · on Zero Trust79 / 100
  • Can we protect ourselves from AI-powered cybercrime?Technology Now · on Zero Trust73 / 100
  • The Strategic Human Firewall as AI Impacts Regulations, Cyber Pros, and Employees - Robert Siciliano - BSW #453Security Weekly Podcast Network · on Zero Trust68 / 100
  • Absolute Security Joins Pax8 (EP 1039)Uncle Marv's IT Business Podcast · on Zero Trust63 / 100

More from Threat Talks

All episodes →
  • Why Do You Trust Your AI Agent?61 / 100
  • Mythos is not the AI Apocalypse80 / 100
  • What about Iran? One Word Document, Three Backdoors76 / 100
  • Europe Is Losing the Sea Cable Race76 / 100
  • Russia Cutting Cables?87 / 100
Explore the best B2B Engineering & DevTools podcasts →
All Threat Talks episodes →