KB-2348 Information about the Salesloft Drift Breach
On 20-Aug-2025, Salesloft announced that a threat actor utilized compromised OAuth credentials for their Drift application in order to exfiltrate data from customer Salesforce environments.
Appian has investigated this incident and is not impacted, as we do not utilize the affected plugin. We will continue to monitor the situation and provide any updates as appropriate.
Additional Notes:
Supporting Documentation:
- https://unit42.paloaltonetworks.com/threat-brief-compromised-salesforce-instances/
- https://trust.salesloft.com/?uid=Drift%2FSalesforce+Security+Notification
Affected Versions
This article applies to all supported versions of Appian.
Last reviewed: September 8, 2025
