Five practical ways for nonprofits to protect Salesforce from data breaches

Blog

Over the past year, several high‑profile organisations have experienced data breaches involving Salesforce integrations – most notably through the Salesloft/Drift OAuth token compromise and a Salesforce Data Loader-related attack involving malicious connected apps. Although these incidents affected major enterprises, non-profits face the same risks – often with fewer security resources.

The good news: practical, achievable steps can dramatically reduce your organisation’s exposure.

Background – what actually happened?

Two separate but related security issues emerged:

1. The Salesloft /Drift OAuth Token Breach

Attackers gained access to Salesloft’s GitHub account, stole code and credentials, and eventually accessed Drift’s AWS environment to extract OAuth tokens* used to connect Drift and Salesforce. They then used these tokens to export sensitive data from hundreds of organisations’ Salesforce environments.

The recent news about an attack on Grubhub and other high profile incidents (notably misuse of tokens associated with the Gainsight connected app) are thought to be linked to this attack.

*An OAuth token provides short-term permission that lets an app access what it needs from Salesforce.

2. The Salesforce Data Loader Malicious App Incident

Attackers tricked users into installing a fake Salesforce connected app that appeared to be ‘Data Loader’. This involved a sophisticated vishing campaign in which attackers called users directly pretending to be IT support. Once installed, this malicious app could sit dormant for months before being used to quietly extract data. There could still be organisations that have this app installed unknowingly.

It is worth noting that both these breaches involved a compromise of third-party apps connecting to Salesforce and not of the Salesforce platform itself.


Five practical steps nonprofits should take now

1. Audit all Connected Apps in Salesforce

Connected Apps act like “fences with gates” – and these breaches exploited gates that organisations didn’t know were open.

Actions to take:

  • Go to Setup → Apps → Connected Apps → Manage Connected Apps
  • Identify anything unfamiliar or unused.
  • Review the OAUTH usage (Connected Apps OAuth Usage page in setup)
  • If you see any connected apps you don’t recognise or no longer used, investigate and if necessary revoke access.
  • Ensure users cannot install connected apps without administrative approval.
  • Review access for each connected app, ensuring these are set to “Admin approved users are pre-authorized” and have associated profiles or permission sets assigned only to users who require access

This step is critical because connected apps were a root cause of Data Loader–related breaches. While Salesforce fully support Connected Apps and these are secure when properly set up, going forward most integrations will use a slightly different approach with External Client Apps which require that apps are configured directly in the org or installed through packages.


2. Review your Third‑Party integrations carefully

Non-profits often adopt tools quickly to support fundraising, marketing, or volunteer engagement. Each tool, however, increases your exposure.

What to do:

  • Maintain a simple register of all systems connected to Salesforce.
  • Ensure each vendor follows secure development practices.
  • Where possible, use a dedicated integration user for each integrated system and configure the permissions associated with each integration user to be the minimal set required for the integration. Avoid broad permissions such as “View or Modify All Data’“ and “Modify Metadata Through Metadata API Functions”.

The Drift breach spread through compromised third-party tokens. Poorly governed integrations are one of the biggest – and most preventable risks.


3. Rotate OAuth tokens and API keys regularly

In the Salesloft/Drift breach, attackers didn’t just steal short-lived access tokens. They obtained long-lived refresh tokens, which could be used repeatedly to generate new access tokens.

What to do:

  • Review connected app policies for refresh tokens. Where possible we’d recommend setting refresh tokens to expire after 90 days to require periodic user re-authorisation of integrations
  • Remove integrations no longer in use.
  • Ask vendors how they secure and refresh OAuth tokens.

This aligns directly with the containment actions taken after the Salesloft/Drift breach.


4. Enable strong access controls

To help avoid data breaches more generally, even if attackers obtain credentials, strong access controls can help reduce the risk.

What to do:

  • Enforce Multi‑Factor Authentication (MFA) for all cloud applications that you use.
  • Ensure users only access the data and functionality they need for their job.
  • Restrict admin rights to the smallest possible group
  • Create an authorisation process to elevate user privileges to admin.

If your organisation handles highly sensitive data or has additional security requirements you could also consider additional monitoring and security focused tooling such as Salesforce Shield or third party monitoring products.


5. Educate staff and volunteers – gently and frequently

Many of these attacks involved social engineering, and in these cases ‘Vishing’, in which an attacker calls a user directly and convinces them to take an action that opens the way to a breach.

Key takeaways
How to spot a vishing attempt – these are some red flags:

  • The caller claims to be from your bank, tech support, Salesforce or even the government.
  • They use urgency or fear – like saying your account will be locked or you’ll be fined.
  • They ask for sensitive info: passwords, PINs, or verification codes.
  • They ask you to install an app
  • The caller ID looks familiar, but seems suspicious.
  • They won’t let you verify their identity or call them back.

If you have any suspicion

  • Stay calm and think critically before acting on any phone request
  • Hang up and verify the caller using a trusted number from the official website
  • Contact your IT team directly and check with them.
  • Share with others to help protect your colleagues

Most breaches begin with human error- not technical failure. Regular, supportive training makes a real difference.

Train your team to:

  • Be cautious of emails prompting them to install apps.
  • Report suspicious Salesforce login notifications.
  • Use unique, strong passwords and MFA everywhere


Final Thoughts

Non-profits don’t need enterprise‑level budgets to protect sensitive data. By taking a few practical steps – auditing apps, rotating tokens, reducing integration risk, strengthening access controls, and training your team – you can dramatically lower your chances of being affected by incidents similar to the Salesloft/Drift OAuth breach or the Data Loader malicious app attack.

If you would like help with this or have other questions about Salesforce security for your nonprofit please don’t hesitate to contact us.

 

About the author:

Stuart Garner is Director of Technical Development at Giveclarity

Written by

Stuart Garner

04/02/2026

Blog