SalesBleed
The SalesBleed campaign targets technology sector organizations by exploiting vulnerabilities within Salesforce Agentforce. Attackers leverage Web-to-Lead forms to facilitate AI agent hijacking and unauthorized data exfiltration. This activity is used to compromise CRM data and distribute phishing messages through integrated enterprise tools like Slack. OffPerimeter analysis indicates this is an active campaign focused on sensitive enterprise information theft.
- First seen
- 2026-06-01
- Last seen
- 2026-09-25
- Threat actors
- —
- Malware
- —
- Sectors
- Technology
- Countries
- —
How it works
The attack chain begins with the exploitation of Salesforce Agentforce via vulnerable Web-to-Lead forms to achieve initial access. Once the AI agent is hijacked, the attackers use the compromised agent to exfiltrate sensitive CRM data. Finally, the actors leverage Slack integrations to distribute phishing messages to internal users to further expand their footprint.
Techniques (MITRE ATT&CK)
- T1190 · Initial AccessExploit Public-Facing ApplicationThe campaign exploits vulnerabilities in Salesforce Agentforce Web-to-Lead forms to gain entry into the environment.
- T1567 · ExfiltrationExfiltration Over Web ServiceAttackers use the hijacked AI agent to exfiltrate sensitive CRM data through web-based channels.
- T1566 · Initial AccessPhishingThe actors distribute phishing messages via Slack integrations to target enterprise employees.
What to do
- Audit and secure all Salesforce Web-to-Lead form configurations.
- Implement strict access controls and monitoring for Salesforce Agentforce AI agents.
- Monitor Slack integrations for unusual data movement or unexpected external communications.
- Enable multi-factor authentication across all CRM and enterprise communication platforms.
- Conduct security reviews of all third-party integrations connected to Salesforce environments.