Salesbleed Campaign Leverages Salesforce AI Agents to Deliver Phishing via Slack
What Happened — Researchers observed a new phishing technique dubbed “Salesbleed” that abuses Salesforce’s AI‑driven agents (e.g., Einstein) to craft malicious instructions. Those instructions are automatically posted to Slack workspaces, appearing as trusted internal communications and prompting users to click malicious links or disclose credentials.
Why It Matters for Trust & Control Assurance —
- The scenario tests the control objective of continuous oversight of third‑party SaaS integrations – a core element of a robust vendor‑risk program.
- It illustrates the need for real‑time monitoring of outbound content from integrated applications to generate defensible audit evidence of due diligence.
- It underscores why security awareness training must evolve to cover AI‑generated social engineering that bypasses traditional email filters.
Who Is Affected — Organizations that rely on Salesforce‑Slack integrations across technology, finance, professional services, and other sectors.
Recommended Actions —
- Inventory all Salesforce‑to‑Slack connections and enforce least‑privilege scopes.
- Deploy DLP or content‑inspection controls on outbound Slack messages originating from automated agents.
- Update security awareness curricula to include AI‑generated phishing vectors and simulate Slack‑based attacks.
Source: Dark Reading
Technical Notes — The attack leverages Salesforce’s “Agentic AI” feature to inject arbitrary web‑sourced instructions into Slack via the platform’s API. No public CVE is associated; the risk stems from misuse of legitimate integration pathways rather than a software flaw. Source: same as above