No core PagerDuty credentials were compromised, but customers should remain vigilant against phishing attempts.
PagerDuty was alerted by Salesloft to a security flaw within the Drift application’s OAuth integration flow with Salesforce.
The situation escalated when Salesloft confirmed that attackers had exploited this flaw—specifically within the OAuth 2.0 authorization code grant process—enabling a threat actor to hijack the token exchange and access PagerDuty’s Salesforce data.
Crucially, PagerDuty’s native credentials, user passwords, and API keys remained secure.
| Date | Event | Technical Impact |
|---|---|---|
| Aug 20, 2025 | PagerDuty notified of Drift security issue | Identification of potential OAuth flow vulnerability |
| Aug 23, 2025 | Salesloft confirms exploitation of OAuth authorization code grant | Possible unauthorized access via compromised access tokens |
| Aug 27, 2025 | Salesloft issues mitigation steps for customers managing own Drift–third-party connections | Recommendation to rotate OAuth client secrets and refresh tokens |
| Aug 29, 2025 | PagerDuty disables Drift’s OAuth integration with Salesforce; investigation continues | Revoked Drift API scopes; ensured principle of least privilege |
Following Salesloft’s advisory, PagerDuty immediately:
Although no passwords or PagerDuty platform credentials were exposed, the OAuth breach may have revealed customer-facing data stored within Salesforce.
The potential data elements include
| Data Type | Description | Recommended Mitigation |
|---|---|---|
| Names | Customer and contact person names | Verify legitimate requests via trusted channels |
| Phone Numbers | Business-line and mobile numbers | Ignore unexpected inbound calls |
| Email Addresses | Notification and support email addresses | Scrutinize email sender domains and URLs |
Given the risk of social engineering, PagerDuty urges all users to exercise heightened caution
PagerDuty remains committed to transparency and rigorous security practices.
We will continue to investigate this incident, update customers on any significant findings, and collaborate with industry partners to strengthen the security posture of integrated applications like Salesloft Drift.
Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates
The post PagerDuty Confirms Breach as Hackers Access Salesforce Accounts appeared first on Cyber Security News.
Witch Hat Atelier is a great manga for newcomers to the medium, and the price…
BIG COUNTRY, Texas (KTAB/KRBC) – The Storm Prediction Center has placed nearly the entire Big…
ABILENE, Texas (KTAB/KRBC) - McMurry University has launched Abilene’s only collegiate gymnastics program. The program…
COLEMAN, Texas (KTAB/KRBC) - As the City of Coleman gets ready to celebrate its 150th…
ABILENE, Texas (KTAB/KRBC) - A new pickleball complex proposed in north Abilene has been given…
Editor’s Note: The Abilene Police Department supplied the following arrest and incident reports. All information…
This website uses cookies.