Some months you can only name in hindsight. August 2025 was the month the year found its method. Between roughly August 8 and 18, a threat actor tracked as UNC6395 got hold of OAuth tokens belonging to Drift — the AI sales chatbot made by Salesloft that thousands of companies had wired into their Salesforce. Those tokens were standing permission: a trusted app's ongoing right to read a company's customer records. With them, the attacker didn't need to break into anything. They logged in as the chatbot and ran quiet queries across Salesforce objects — Accounts, Cases, Users — pulling out exactly the secrets that lubricate the rest of an attack: AWS keys, Snowflake credentials, passwords, API tokens.

The scale is what made it a landmark. Google's threat researchers put the number of potentially affected organisations north of 700 — a single compromised integration turned into a skeleton key for hundreds of enterprises at once. On August 20, Salesloft and Salesforce revoked every Drift token and pulled the app from the marketplace, but by then the pattern was set for the year: the modern breach is not a wall being scaled, it is a guest badge being borrowed. You harden your fortress for a decade and then hand a plastic keycard to a chatbot, and the chatbot is where the thieves wait.

Everything that followed in 2025 and beyond rhymed with August. The Gainsight token revocations of November, the Klue OAuth raid of the next June, the whole ShinyHunters franchise — all of them are August's lesson, taught again to a new roster of victims each time. If a single month can be said to have written a year's threat playbook, this was it.

Also that month · The quiet exfiltration

Secrets, not just records

What made the Drift campaign so dangerous wasn't the customer data — it was the credentials tucked inside it. Support cases and CRM notes are where careless engineers paste access keys "just to get it working," and the attacker knew exactly what to grep for. A breach that starts in a chatbot's token and ends with your cloud keys is a breach that keeps going long after the first door is closed. August's real lesson for defenders: your CRM is a credential store you forgot you were running.

Also that month · The pattern names itself

OAuth abuse enters the mainstream

Before August 2025, "OAuth token abuse" was a phrase for security conference tracks. After it, the phrase turned up in board decks, cyber-insurance questionnaires, and CISO briefings worldwide. The industry began, belatedly, to inventory its SaaS-to-SaaS connections — the sprawling, unmapped web of apps granted standing access to other apps — and mostly discovered it had no idea how many keys it had handed out, or to whom. That inventory problem became one of 2026's defining security projects, and it started here.

India desk · August 2025

SaaS nation, meet SaaS risk

Few economies had wired themselves into cloud SaaS faster than India's — every startup, GCC, and modern enterprise running on Salesforce, Google Workspace, and a constellation of integrations bolted on for convenience. August's Drift campaign was a warning shot aimed squarely at that architecture: the same OAuth grants that let an Indian firm move fast let an attacker move faster. Against a backdrop where the DPDP Act had just become law weeks earlier, the breach underlined an awkward truth for Indian data fiduciaries — you are responsible for personal data that can walk out through an app you integrated and forgot, and "our vendor's chatbot did it" is not a defence the law recognises.

⏳ Time capsule — August 2025

  • "OAuth" went from developer jargon to boardroom vocabulary in a single news cycle.
  • The Nx build-system compromise late in the month seeded the Shai-Hulud worm that would erupt in September — the supply-chain story warming up.
  • UNC-numbered threat clusters became household names in security circles, as attribution outpaced arrests.
  • Security teams returning from summer holidays came back to a new chore: auditing every "Connected App" in their Salesforce org.
Where it stands today — 2026

The year's Rosetta Stone

If you want to read 2025 and 2026, start with August. The Drift breach was the Rosetta Stone that made every later incident legible: borrowed keys, trusted integrations, standing permissions abused at scale. Its direct descendants fill this archive — November's Gainsight, the next spring's classroom and HR-software raids, June's Klue attack on the security industry's own vendors. The defensive response it forced — treat every OAuth grant as a credential, inventory the SaaS-to-SaaS mesh, revoke ruthlessly — is now standard practice, and standard because of the 700 companies that learned it the hard way this month. The fortress never fell. Someone just kept walking in the front door with a badge it had issued.