# The CRM Goldmine: Inside the Salesforce Breach Wave Page: https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/the-crm-goldmine-inside-the-salesforce-breach-wave Text version: https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/the-crm-goldmine-inside-the-salesforce-breach-wave.md Podcast: [Cyberside Chats: Cybersecurity Insights from the Experts](https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591) Published: 2026-06-02T10:30:00+00:00 Episode link: https://www.chatcyberside.com/e/the-crm-goldmine-inside-the-salesforce-breach-wave/ Audio file: https://mcdn.podbean.com/mf/web/8zv5af78jyemiuix/EP75_-_crm_targets7xj6h.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/the-crm-goldmine-inside-the-salesforce-breach-wave Duration seconds: 991 ## Resource It started with a phone call. No malware, no zero-day — just someone talking a Charter worker out of their login. Months later, 4.9 million customer records surfaced on a leak site, pulled from the company's Salesforce instance. The CRM has become the richest target in enterprise security. Sherri and Matt break down why, and walk through three cases: Charter, where one vished login reached everything; the Salesloft Drift and Gainsight chain, where one stolen token unlocked the next breach and the next; and the Salesforce "Aura" campaign, where misconfigured guest accounts exposed hundreds of organizations — including, ironically, identity-protection company Aura. The throughline: Salesforce wasn't breached, the tenants were — and in every case, nobody was watching the data leave. Key Takeaways 1. Govern your CRM as carefully as your email and file storage. You already wrap M365 or Google Workspace in conditional access, audit logs, and DLP. Your CRM holds data just as sensitive — give it the same controls. 2. Lock down who can log in. Enforce phishing-resistant MFA and verify identity before granting access — almost every CRM breach this year started with one compromised or socially-engineered login. 3. Least privilege limits the blast radius. One identity should never reach the entire instance, and a guest user should never touch live records. Provision for the job, not for convenience. 4. Inventory your connected apps and OAuth tokens, and revoke the ones that don't need access or can't be accounted for. Your perimeter now includes software you didn't write; a forgotten token walks straight past MFA and SSO. 5. Watch the exits, not just the entrance. Someone will always get in. Set export caps, alert on anomalous volume, and turn on the SaaS DLP you already own — alm… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/episodes/the-crm-goldmine-inside-the-salesforce-breach-wave/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/cyberside-chats-cybersecurity-insights-from-the-experts-7144591/the-crm-goldmine-inside-the-salesforce-breach-wave.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.