TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Trend Micro Research

Domino Effect: How One Vendor's AI App Breach Toppled Giants

Fernando Tucci · 2025-09-24 · Read original ↗

ATT&CK techniques detected

7 predictions
T1199Trusted Relationship
78%
“ways traditional security models never anticipated. the kill chain : how the breach unfolded the attack was a classic domino effect, starting from a single point of weakness and cascading through the supply chain. according to investigations, the threat actor ( tracked as unc6395…”
T1195Supply Chain Compromise
48%
“domino effect : how one vendor ' s ai app breach toppled giants artificial intelligence ( ai ) domino effect : how one vendor ' s ai app breach toppled giants a single ai chatbot breach at salesloft - drift exposed data from 700 + companies, including security leaders. the attack…”
T1528Steal Application Access Token
47%
“ways traditional security models never anticipated. the kill chain : how the breach unfolded the attack was a classic domino effect, starting from a single point of weakness and cascading through the supply chain. according to investigations, the threat actor ( tracked as unc6395…”
T1199Trusted Relationship
45%
“8 - 18 ) : the attackers systematically used this access to exfiltrate data from the connected salesforce instances of numerous customers. the victims were not just salesloft and drift, but a roster of industry leaders including palo alto networks, cloudflare, and zscaler, who ha…”
T1550.001Application Access Token
37%
“ways traditional security models never anticipated. the kill chain : how the breach unfolded the attack was a classic domino effect, starting from a single point of weakness and cascading through the supply chain. according to investigations, the threat actor ( tracked as unc6395…”
T1671Cloud Application Integration
36%
“ways traditional security models never anticipated. the kill chain : how the breach unfolded the attack was a classic domino effect, starting from a single point of weakness and cascading through the supply chain. according to investigations, the threat actor ( tracked as unc6395…”
T1195.002Compromise Software Supply Chain
31%
“ways traditional security models never anticipated. the kill chain : how the breach unfolded the attack was a classic domino effect, starting from a single point of weakness and cascading through the supply chain. according to investigations, the threat actor ( tracked as unc6395…”

Summary

A single AI chatbot breach at Salesloft-Drift exposed data from 700+ companies, including security leaders. The attack shows how AI integrations expand risk, and why controls like IP allow-listing, token security, and monitoring are critical.