{
  "type": "bundle",
  "id": "bundle--00944ce8-0101-42b8-8195-fe500195ffa0",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2025-09-06T00:00:00.000Z",
      "modified": "2025-09-06T00:00:00.000Z",
      "name": "Optimus Labs · Civilizations",
      "identity_class": "organization",
      "description": "Threat research team at Optimus Labs. Agentic AI attack surface research.",
      "contact_information": "https://www.optimuslabs.io/research/briefings"
    },
    {
      "type": "report",
      "spec_version": "2.1",
      "id": "report--33308068-0101-4b44-8231-bb2c3431bbac",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2025-09-06T00:00:00.000Z",
      "modified": "2025-09-06T00:00:00.000Z",
      "name": "Stolen OAuth Tokens Let Attackers Loot 700+ CRMs via AI Chatbot",
      "description": "Attackers compromised Salesloft's GitHub, moved into Drift's AWS, and stole the OAuth tokens Drift's AI chatbot held for customer Salesforce instances. The tokens were already trusted. No credentials to crack.\n\nDrift is an AI-powered conversational sales chatbot (acquired by Salesloft in 2024) deployed across thousands of enterprise websites with read/write OAuth grants into customer CRMs. Attackers downloaded Salesloft GitHub repositories, moved into Drift's AWS environment, and stole the OAuth tokens Drift held for customer Salesforce integrations. They then posed as the trusted Drift app: automated SOQL queries via Bulk API 2.0 pulled contacts, accounts, opportunities and support cases. Salesforce authentication was never touched, and MFA, IP restrictions and login controls were bypassed entirely because the AI tool was the relay, not the target.",
      "published": "2025-09-06T00:00:00.000Z",
      "report_types": [
        "threat-report"
      ],
      "confidence": 85,
      "labels": [
        "Supply chain",
        "Vendor breach",
        "Shadow AI",
        "Supply Chain nth Party Risk",
        "AI Asset Supply Chain Security",
        "Agent Permissions",
        "Outside the Agentic Loop",
        "severity:critical"
      ],
      "object_refs": [
        "indicator--0487c694-0102-4df7-8585-cb630589d48b",
        "indicator--f30c8367-0102-4305-8df1-5f9ef40ea66c",
        "software--b4dd69dc-0101-4e44-84a2-37868b5df582",
        "software--f4369af2-0101-4bae-8ac8-fea4f53836a0",
        "software--0c49cdf8-0102-4043-8d4b-cdbb0d4bce3b",
        "software--64d8d74c-0101-4973-85d9-7e3f65da80bf",
        "software--feab0f40-0101-4c19-8-55-9ca7ffac7b59"
      ],
      "external_references": [
        {
          "source_name": "Optimus Labs · Civilizations",
          "url": "https://www.optimuslabs.io/research/briefings/salesloft-drift-oauth-supply-chain"
        },
        {
          "source_name": "Anomali — chain analysis with MITRE mapping",
          "url": "https://www.anomali.com/blog/salesloft-drift-breach-recap"
        },
        {
          "source_name": "UpGuard — breach analysis, victim list, 700+ orgs",
          "url": "https://www.upguard.com/blog/salesloft-drift-breach"
        },
        {
          "source_name": "SOCRadar — disclosure analysis and exposed data inventory",
          "url": "https://socradar.io/blog/salesloft-drift-breach-everything-you-need-to-know"
        },
        {
          "source_name": "ProcessUnity — third-party risk lessons",
          "url": "https://www.processunity.com/resources/blogs/lessons-from-drift-salesloft-breach"
        },
        {
          "source_name": "FINRA — regulatory alert",
          "url": "https://www.finra.org/rules-guidance/guidance/salesloft-drift-AI-supply-chain-attack"
        }
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--0487c694-0102-4df7-8585-cb630589d48b",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2025-09-06T00:00:00.000Z",
      "modified": "2025-09-06T00:00:00.000Z",
      "name": "ipv4: 208.68.36.90",
      "description": "IP: 208.68.36.90 (DigitalOcean)",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[ipv4-addr:value = '208.68.36.90']",
      "pattern_type": "stix",
      "valid_from": "2025-09-06T00:00:00.000Z",
      "labels": [
        "salesloft-drift-oauth-supply-chain",
        "supply-chain",
        "vendor-breach",
        "shadow-ai"
      ]
    },
    {
      "type": "indicator",
      "spec_version": "2.1",
      "id": "indicator--f30c8367-0102-4305-8df1-5f9ef40ea66c",
      "created_by_ref": "identity--b106305c-0100-414a-84ff-91eeab20701a",
      "created": "2025-09-06T00:00:00.000Z",
      "modified": "2025-09-06T00:00:00.000Z",
      "name": "ipv4: 44.215.108.109",
      "description": "IP: 44.215.108.109 (AWS)",
      "indicator_types": [
        "compromised",
        "malicious-activity"
      ],
      "pattern": "[ipv4-addr:value = '44.215.108.109']",
      "pattern_type": "stix",
      "valid_from": "2025-09-06T00:00:00.000Z",
      "labels": [
        "salesloft-drift-oauth-supply-chain",
        "supply-chain",
        "vendor-breach",
        "shadow-ai"
      ]
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--b4dd69dc-0101-4e44-84a2-37868b5df582",
      "name": "Salesloft"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--f4369af2-0101-4bae-8ac8-fea4f53836a0",
      "name": "Drift"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--0c49cdf8-0102-4043-8d4b-cdbb0d4bce3b",
      "name": "Salesforce"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--64d8d74c-0101-4973-85d9-7e3f65da80bf",
      "name": "GitHub"
    },
    {
      "type": "software",
      "spec_version": "2.1",
      "id": "software--feab0f40-0101-4c19-8-55-9ca7ffac7b59",
      "name": "AWS"
    }
  ]
}