Market Cap: $4.0721T 0.06%
Volume(24h): $143.4585B -17.01%
  • Market Cap: $4.0721T 0.06%
  • Volume(24h): $143.4585B -17.01%
  • Fear & Greed Index:
  • Market Cap: $4.0721T 0.06%
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
Top News
Cryptos
Topics
Cryptospedia
News
CryptosTopics
Videos
bitcoin
bitcoin

$115849.501581 USD

-0.20%

ethereum
ethereum

$4657.446044 USD

-1.30%

xrp
xrp

$3.094289 USD

-0.74%

tether
tether

$1.000313 USD

-0.03%

solana
solana

$243.548889 USD

0.20%

bnb
bnb

$930.722647 USD

0.20%

usd-coin
usd-coin

$0.999696 USD

-0.01%

dogecoin
dogecoin

$0.283551 USD

1.29%

tron
tron

$0.349632 USD

-0.77%

cardano
cardano

$0.915982 USD

-1.94%

hyperliquid
hyperliquid

$54.899464 USD

-0.88%

chainlink
chainlink

$24.718086 USD

-1.68%

ethena-usde
ethena-usde

$1.001078 USD

-0.02%

sui
sui

$3.756062 USD

0.14%

stellar
stellar

$0.399024 USD

-1.87%

Cryptocurrency News Articles

Salesloft, Drift, Breach Timeline: What You Need to Know

Sep 13, 2025 at 04:08 am

A deep dive into the Salesloft Drift breach, its timeline, and the widespread impact on cybersecurity companies. Stay informed on this critical supply chain attack.

Salesloft, Drift, Breach Timeline: What You Need to Know

The Salesloft Drift breach sent shockwaves through the cybersecurity world. With over 700 organizations affected, understanding the timeline and impact is crucial. Here's a breakdown of what happened.

The Breach: A Timeline of Events

The Salesloft Drift breach is a complex story unfolding over several months. Here's a simplified timeline:

  • March 2025: Threat actors compromise Salesloft's GitHub account.
  • March - June 2025: Attackers download repository data and conduct reconnaissance on Salesloft and Drift environments.
  • August 8-18, 2025: Using stolen OAuth tokens, attackers access and exfiltrate data from customer Salesforce instances.
  • August 20, 2025: Salesloft and Salesforce revoke connections between Drift and Salesforce.
  • August 26, 2025: Companies announce unauthorized access. Google warns of credential theft.
  • August 28, 2025: Salesloft begins investigation with Mandiant.
  • September 2-8, 2025: Cybersecurity firms including Palo Alto Networks, Zscaler, Cloudflare, Proofpoint, Tenable, Qualys, Rubrik, Spycloud, BeyondTrust, CyberArk, Elastic, Dynatrace, Cato Networks and BugCrowd disclose they were victims.
  • September 6, 2025: Salesloft confirms GitHub compromise as the initial attack vector.
  • September 8, 2025: Salesforce restores integration with Salesloft (excluding Drift).

Key Insights and Takeaways

The Salesloft Drift breach underscores several critical points:

  • Supply Chain Risks: Third-party integrations, especially in SaaS environments, introduce significant risks.
  • OAuth Token Security: Stolen OAuth tokens are a powerful attack vector, granting access without triggering typical alerts.
  • Importance of Incident Response: Swift action, including isolating infrastructure and rotating credentials, is crucial in containing breaches.
  • GitHub as a Target: This incident highlights the growing trend of attackers targeting code repositories like GitHub.

The Impact on Cybersecurity Companies

A particularly alarming aspect of this breach is the number of cybersecurity companies affected, including Cloudflare, Zscaler, Palo Alto Networks and many others. This suggests a deliberate targeting of organizations with access to sensitive data and security infrastructure. While these companies took quick action to mitigate impact on products and services, the potential reputational damage and cost of remediation are substantial.

My Two Cents: A Wake-Up Call

The Salesloft Drift breach serves as a potent reminder of the interconnectedness of the modern SaaS ecosystem. It's no longer enough to focus solely on your own security posture; you must also rigorously assess the security practices of your vendors. Assume compromise and ensure proper segmentation and monitoring are in place. Ignoring the reality of supply chain risk is a recipe for disaster.

Salesforce Restores Salesloft Integration

After investigation, Salesforce has restored integration with the Salesloft platform, while the Drift component remains disabled. The incident highlights the potential fallout of third-party application integrations, particularly with popular tools such as Salesloft and Drift.

What's Next?

The investigation into the Salesloft Drift breach is ongoing. Expect further disclosures and analysis as more details emerge. In the meantime, take this as a learning opportunity to bolster your own security defenses.

So, yeah, maybe double-check those third-party app permissions? Just a thought. Stay safe out there, folks!

Original source:techtarget

Disclaimer:info@kdj.com

The information provided is not trading advice. kdj.com does not assume any responsibility for any investments made based on the information provided in this article. Cryptocurrencies are highly volatile and it is highly recommended that you invest with caution after thorough research!

If you believe that the content used on this website infringes your copyright, please contact us immediately (info@kdj.com) and we will delete it promptly.

Other articles published on Sep 14, 2025