A recent security incident involving the third-party marketing application Salesloft Drift has prompted swift action and rigorous internal review.
On August 28, 2025, Zscaler’s security team was alerted to a targeted campaign aimed at Salesloft Drift, a SaaS offering that integrates with Salesforce via OAuth 2.0 for sales workflow automation.
Threat actors successfully exfiltrated OAuth tokens used by Salesloft Drift to access Salesforce customer data.
These tokens operate under the following HTTP header format in API calls:
textGET /services/data/vXX.X/sobjects/Lead HTTP/1.1
Host: yourInstance.salesforce.com
Authorization: Bearer <OAuthAccessToken>
Zscaler confirmed that its own Salesforce instance was among those impacted.
Importantly, no Zscaler products, services, or infrastructure were compromised; the breach vector was confined strictly to credentials managed by Salesloft Drift.
Following detection, Zscaler conducted a detailed forensic investigation in collaboration with Salesforce security analysts.
The scope of unauthorized access was limited to non-sensitive Salesforce records, including:
There is currently no evidence of data misuse or exfiltration beyond token theft.
However, as a precaution, Zscaler executed the following mitigation measures:
curl -X POST https://yourInstance.salesforce.com/services/oauth2/revoke -d token=<OAuthAccessToken>Although no misuse has been detected, vigilance is paramount. Zscaler advises all customers to:
OAuthTokenRevocationEvent and LoginEvent logs for anomalies.api, refresh_token) and disable unused permissions.Zscaler remains dedicated to securing customer environments and will provide additional updates as the investigation evolves.
For further assistance, contact Zscaler Support via help.zscaler.com or your existing support channels. Your security is our highest priority.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates
The post Zscaler Confirms Data Breach – Hackers Compromised Salesforce Instance appeared first on Cyber Security News.
The Star Trek franchise is at a moment of uncertainty: For the first time since…
The Star Trek franchise is at a moment of uncertainty: For the first time since…
The Star Trek franchise is at a moment of uncertainty: For the first time since…
Marvel Studios will return for San Diego Comic-Con 2026. According to The Wrap, Marvel will…
Marvel Studios will return for San Diego Comic-Con 2026. According to The Wrap, Marvel will…
Marvel Studios will return for San Diego Comic-Con 2026. According to The Wrap, Marvel will…
This website uses cookies.