Episode

The CRM Goldmine: Inside the Salesforce Breach Wave

Podcast
Cyberside Chats: Cybersecurity Insights from the Experts
Published
Jun 2, 2026
Duration seconds
991
Processing state
not_requested
Canonical source
https://www.chatcyberside.com/e/the-crm-goldmine-inside-the-salesforce-breach-wave/
Audio
https://mcdn.podbean.com/mf/web/8zv5af78jyemiuix/EP75_-_crm_targets7xj6h.mp3
JSON
/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/the-crm-goldmine-inside-the-salesforce-breach-wave
Markdown
/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/the-crm-goldmine-inside-the-salesforce-breach-wave.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/the-crm-goldmine-inside-the-salesforce-breach-wave/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/the-crm-goldmine-inside-the-salesforce-breach-wave.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

It started with a phone call. No malware, no zero-day — just someone talking a Charter worker out of their login. Months later, 4.9 million customer records surfaced on a leak site, pulled from the company's Salesforce instance. The CRM has become the richest target in enterprise security. Sherri and Matt break down why, and walk through three cases: Charter, where one vished login reached everything; the Salesloft Drift and Gainsight chain, where one stolen token unlocked the next breach and the next; and the Salesforce "Aura" campaign, where misconfigured guest accounts exposed hundreds of organizations — including, ironically, identity-protection company Aura. The throughline: Salesforce wasn't breached, the tenants were — and in every case, nobody was watching the data leave. Key Takeaways 1. Govern your CRM as carefully as your email and file storage. You already wrap M365 or Google Workspace in conditional access, audit logs, and DLP. Your CRM holds data just as sensitive — give it the same controls. 2. Lock down who can log in. Enforce phishing-resistant MFA and verify identity before granting access — almost every CRM breach this year started with one compromised or socially-engineered login. 3. Least privilege limits the blast radius. One identity should never reach the entire instance, and a guest user should never touch live records. Provision for the job, not for convenience. 4. Inventory your connected apps and OAuth tokens, and revoke the ones that don't need access or can't be accounted for. Your perimeter now includes software you didn't write; a forgotten token walks straight past MFA and SSO. 5. Watch the exits, not just the entrance. Someone will always get in. Set export caps, alert on anomalous volume, and turn on the SaaS DLP you already own — alm…