Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused
Google's threat intelligence group reported that stolen credentials for the Salesloft Drift conversational agent were used to export data from hundreds of organisations' customer platforms. The integration held its own identity, its queries were visible in per connection audit logs, and on 20 August 2025 every access and refresh token for the application was revoked. Prevention failed; detection and revocation worked.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0014
- Kind
- Exfiltration
- Jurisdiction
- United States
- Last verified
- Added
- Google reports that on 20 August 2025 the vendor, working with the platform, revoked all active access and refresh tokens for the agent application.
- Google identified affected users, revoked the specific tokens granted to the agent's email integration and disabled the integration pending investigation.
- The guidance tells operators to review platform event monitoring logs for unusual activity associated with the agent's connection user.
- The integration held a distinct connected application identity, so its queries were separable from human activity in the logs.
- The stolen tokens carried broad scopes that allowed bulk export without any further check.
Dimension by dimension
7 dimensions, each one stated, silent or open
Identity, Logging and audit, Revocation, Authorization, Limits, Human approval, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentityStated
- The integration held its own connected application principal, distinguishable in logs from human users, which is what made the investigation possible.Google Threat Intelligence Group, data theft via Salesloft Drift, primary source, 26 August 2025.
- Logging and auditStated
- Per connection event monitoring recorded the agent's queries, and that record is how the scope of the theft was reconstructed.Google Threat Intelligence Group, data theft via Salesloft Drift, primary source, 26 August 2025.
- RevocationStated
- All access and refresh tokens were revoked on a named date and the integration was disabled.Google Threat Intelligence Group, data theft via Salesloft Drift, primary source, 26 August 2025.
- AuthorizationSilent
- The token's granted scopes allowed bulk export from hundreds of organisations with no further check.Google Threat Intelligence Group, data theft via Salesloft Drift, primary source, 26 August 2025.
- LimitsSilent
- No rate, volume or egress bound stopped mass export over a period of days.Google Threat Intelligence Group, data theft via Salesloft Drift, primary source, 26 August 2025.
- Human approvalSilent
- No step required a person to approve the bulk queries the agent's credential ran.Google Threat Intelligence Group, data theft via Salesloft Drift, primary source, 26 August 2025.
- AccountabilityStated
- The investigating vendor published attribution and per customer notification steps.Google Threat Intelligence Group, data theft via Salesloft Drift, primary source, 26 August 2025.
Figures
Every number, with who measured it and when
- 700 organisations
Organisations Google states were affected
Google Threat Intelligence Group, data theft via Salesloft Drift, primary source, as of .
What it changes
For a team deploying an agent
This is the ledger's clearest case of controls doing real work, and of which ones. Give every agent integration its own identity, keep its activity in a log you can query by that identity, and rehearse revoking its tokens. Those three are what bounded this. The two that failed are the ones to fix first: scope the grant to the records the agent needs, and put a volume ceiling on bulk export.
Sources
What this record was verified against
- Google Threat Intelligence Group, data theft via Salesloft DriftPrimary · 26 August 2025
Related
Records that sit beside this one
A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats
United States · verified 15 September 2026
The researchers write that they entered the same six digit string as username and password and were immediately logged in.
Does any published standard require an agent to hold an identity distinct from the person it acts for?
Global · verified 15 September 2026
The Model Context Protocol authorization specification states that clients must implement resource indicators for OAuth so that a token names the resource it is for.
A support agent invented a policy its company did not have, and customers cancelled over it
United States · verified 15 September 2026
A company representative stated publicly that there is no such policy and that users are free to use the product on multiple machines.
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
United States · verified 15 September 2026
The vendor's own account states that the out of office reply never gets written and the agent resigns on behalf of the user instead.
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely
United States · verified 15 September 2026
The Register reports that the attacker hides the commands in plain English in the issue body and the agent then posts the data as a public comment.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0014 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0014-salesloft-drift-oauth-tokens-revoked-after-mass-export
- MLA
- "Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0014-salesloft-drift-oauth-tokens-revoked-after-mass-export.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0014-salesloft-drift-oauth-tokens-revoked-after-mass-export.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0014-salesloft-drift-oauth-tokens-revoked-after-mass-export
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for United States and every exfiltration record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.