Salesloft Hack: Untangling the Web of Cybercrime Groups and the Rise of “Authorization Sprawl”
The recent breach at Salesloft,a leading sales engagement platform,has sent ripples through the cybersecurity community. While the full scope of the incident is still unfolding, it’s become clear this wasn’t a typical attack. It highlights a hazardous trend: sophisticated threat actors exploiting legitimate access rather than relying on traditional malware. Let’s break down what happened, who might be involved, and why this type of attack is becoming increasingly common.
What Happened wiht Salesloft?
On August 27th, Salesloft announced a security incident impacting its Drift authentication tokens. This allowed attackers to gain unauthorized access to customer data. The company quickly engaged Mandiant, Google Cloud’s incident response team, to investigate. The investigation is ongoing, with more details expected to emerge in the coming days.
Who’s Behind the Attack? A Complex picture
Pinpointing the exact perpetrators is proving challenging. Several groups are being discussed, and the lines are blurring. Here’s a look at the key players and connections:
ShinyHunters: This group is known for data theft and selling stolen credentials on dark web forums.
Scattered Spider: An extortion group notorious for social engineering attacks and targeting credentials. Security researchers believe there’s a significant overlap in the tactics, techniques, and procedures (TTPs) used by both ShinyHunters and Scattered Spider, suggesting a possible connection.
“Scattered LAPSUS$ Hunters 4.0”: A newly formed Telegram channel (now boasting nearly 40,000 subscribers) claiming responsibility for the Salesloft hack. Though, they haven’t provided concrete evidence to support their claims. This group is also attempting to gain attention by threatening security researchers and promoting a new cybercrime forum called “Breachstars.”
Currently, google’s threat intelligence group, led by Austin Larsen, finds no compelling evidence linking the Salesloft incident to either ShinyHunters or othre known groups. Their assessment suggests the Telegram group’s claims are based on publicly available information.
The Key to Their Success: “Authorization Sprawl”
So, how are these groups succeeding? A critical concept to understand is “authorization sprawl.” coined by Joshua Wright, Senior Technical Director at Counter Hack, it describes the problem of excessive and frequently enough poorly managed user access permissions.
Here’s how it works:
Abuse of Legitimate Access: Instead of trying to break into systems, attackers exploit existing, legitimate user access tokens.
Seamless Movement: This allows them to move effortlessly between on-premises and cloud environments.
Stealthy Operations: As the attacker operates within the bounds of authorized access, their activity frequently enough goes undetected.
As Wright explains,attackers are leveraging centralized identity platforms with single sign-on (SSO) and integrated authentication. They’re using the resources already available to authorized users, rather than creating custom malware. This makes detection considerably harder.
Why is this happening now?
The rise of cloud computing, SSO, and increasingly complex identity management systems have inadvertently created fertile ground for this type of attack. Organizations are struggling to keep pace with managing access permissions effectively.
What Can You Do to Protect yourself?
If you’re a Salesloft customer, or use similar platforms, here are some steps you should consider:
Review Access Permissions: Regularly audit and restrict user access to the minimum necessary. Implement the principle of least privilege.
Multi-Factor Authentication (MFA): Enforce MFA on all accounts,especially those with privileged access. Monitor for Anomalous Activity: Implement robust monitoring and alerting systems to detect unusual login attempts or data access patterns.
Stay Informed: Keep up-to-date on the latest security threats and best practices. Follow reputable security blogs (like KrebsOnSecurity!) and vendor advisories.
* Incident Response Plan: Ensure you have a well-defined incident response plan in place, so you can react quickly and effectively in the event of a breach.
The Investigation Continues
Mandiant is actively investigating the root cause of the Salesloft breach. We expect more details to emerge soon, which will hopefully shed more light on the attack vector and the perpetrators involved.
This incident serves as a stark reminder that traditional security
Worth a look