Home › Intelligence › Brief
BREACH BRIEF🟠 High ThreatIntel

Salesbleed Campaign Leverages Salesforce AI Agents to Deliver Phishing via Slack

Researchers identified a new phishing method that abuses Salesforce’s AI agents to post malicious messages into Slack channels. The technique highlights gaps in SaaS integration oversight and the need for updated awareness training, a concern for audit readiness across frameworks.

LiveThreat™ Intelligence · 📅 September 25, 2026· 📰 darkreading.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
2 sector(s)
✅
Actions
3 recommended
📰
Source
darkreading.com

Salesbleed Campaign Leverages Salesforce AI Agents to Deliver Phishing via Slack

What Happened — Researchers observed a new phishing technique dubbed “Salesbleed” that abuses Salesforce’s AI‑driven agents (e.g., Einstein) to craft malicious instructions. Those instructions are automatically posted to Slack workspaces, appearing as trusted internal communications and prompting users to click malicious links or disclose credentials.

Why It Matters for Trust & Control Assurance —

  • The scenario tests the control objective of continuous oversight of third‑party SaaS integrations – a core element of a robust vendor‑risk program.
  • It illustrates the need for real‑time monitoring of outbound content from integrated applications to generate defensible audit evidence of due diligence.
  • It underscores why security awareness training must evolve to cover AI‑generated social engineering that bypasses traditional email filters.

Who Is Affected — Organizations that rely on Salesforce‑Slack integrations across technology, finance, professional services, and other sectors.

Recommended Actions —

  • Inventory all Salesforce‑to‑Slack connections and enforce least‑privilege scopes.
  • Deploy DLP or content‑inspection controls on outbound Slack messages originating from automated agents.
  • Update security awareness curricula to include AI‑generated phishing vectors and simulate Slack‑based attacks.

Source: Dark Reading

Technical Notes — The attack leverages Salesforce’s “Agentic AI” feature to inject arbitrary web‑sourced instructions into Slack via the platform’s API. No public CVE is associated; the risk stems from misuse of legitimate integration pathways rather than a software flaw. Source: same as above

📰 Original Source
https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

Point-in-time vendor reviews miss incidents like this.

Verisq AI Trust Operations replaces the annual questionnaire with continuous third-party monitoring — so vendor exposure becomes audit evidence, not a once-a-year guess.

See how Verisq AI Trust Operations works →