A recent security incident involving the third-party marketing application Salesloft Drift has prompted swift action and rigorous internal review.
On August 28, 2025, Zscaler’s security team was alerted to a targeted campaign aimed at Salesloft Drift, a SaaS offering that integrates with Salesforce via OAuth 2.0 for sales workflow automation.
Threat actors successfully exfiltrated OAuth tokens used by Salesloft Drift to access Salesforce customer data.
These tokens operate under the following HTTP header format in API calls:
textGET /services/data/vXX.X/sobjects/Lead HTTP/1.1
Host: yourInstance.salesforce.com
Authorization: Bearer <OAuthAccessToken>
Zscaler confirmed that its own Salesforce instance was among those impacted.
Importantly, no Zscaler products, services, or infrastructure were compromised; the breach vector was confined strictly to credentials managed by Salesloft Drift.
Following detection, Zscaler conducted a detailed forensic investigation in collaboration with Salesforce security analysts.
The scope of unauthorized access was limited to non-sensitive Salesforce records, including:
There is currently no evidence of data misuse or exfiltration beyond token theft.
However, as a precaution, Zscaler executed the following mitigation measures:
curl -X POST https://yourInstance.salesforce.com/services/oauth2/revoke -d token=<OAuthAccessToken>Although no misuse has been detected, vigilance is paramount. Zscaler advises all customers to:
OAuthTokenRevocationEvent and LoginEvent logs for anomalies.api, refresh_token) and disable unused permissions.Zscaler remains dedicated to securing customer environments and will provide additional updates as the investigation evolves.
For further assistance, contact Zscaler Support via help.zscaler.com or your existing support channels. Your security is our highest priority.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates
The post Zscaler Confirms Data Breach – Hackers Compromised Salesforce Instance appeared first on Cyber Security News.
It's been a few months since Brandon Sanderson officially confirmed he'd be working with Apple…
Cooler Master's NR2 series PCs offer plenty of gaming prowess in a compact 18-liter chassis.…
One of the biggest debates surrounding the Switch 2 has been whether the console has…
A bunch of popular PC titles are discounted today, including our top game of 2025,…
Subnautica 2 has hit almost half a million concurrent players on Steam in its first…
A cybercrime operation is turning software supply chain attacks into a public competition. TeamPCP, in…
This website uses cookies.