Categories: Cyber Security News

HackerOne Confirms Data Breach – Hackers Gained Unauthorized Access To Salesforce Instance

HackerOne has confirmed it was among the companies affected by a recent data breach that provided unauthorized access to its Salesforce instance. The access was gained through a compromise of the third-party application Drift, which Salesloft owns.

The bug bounty platform announced the security incident, aligning with its company value of “Default to Disclosure.” According to the company, its security team was first notified of a potential compromise by Salesforce on Friday, August 22, 2025.

Sponsored

This was subsequently confirmed by Salesloft the following day, prompting HackerOne to activate its incident response protocols immediately.

The company is working in partnership with both Salesforce and Salesloft to investigate the full scope and impact of the breach. This incident is part of a broader attack campaign that has impacted hundreds of companies.

HackerOne Confirms Data Breach

As detailed in a report by Google’s Mandiant, threat actors targeted Salesforce customer records by exploiting a vulnerability within the Drift marketing and sales application.

By compromising Drift, attackers were able to pivot and gain unauthorized access to connected Salesforce environments, allowing for the theft of sensitive customer and sales data.

HackerOne’s confirmation places it on a growing list of firms responding to this supply chain attack. While the investigation remains ongoing, HackerOne stated that a subset of records within its Salesforce instance was accessed by the unauthorized parties.

However, the company expressed confidence that no customer vulnerability data was impacted or exposed during the incident.

Sponsored

This is attributed to the firm’s strict internal policies and controls, which govern data segmentation, effectively siloing sensitive vulnerability information away from the compromised sales and marketing data in the Salesforce environment.

HackerOne is continuing to conduct a forensic analysis on the specific records accessed to determine the exact nature of the exposed information.

The company has committed to communicating directly with any customers who are identified as being impacted by the breach.

This incident highlights the significant risks associated with third-party application integrations and the potential for supply chain attacks to bypass an organization’s direct security defenses.

Find this Story Interesting! Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

The post HackerOne Confirms Data Breach – Hackers Gained Unauthorized Access To Salesforce Instance appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Save 15% Off mfish’s Stylish USB-C Power Banks, Chargers, and Cables

Tired of the same old black brick of a power bank that litters the marketplace?…

27 minutes ago

Kunce “ready for the challenge” of task of rebuilding South Beloit Fire Departmen

Kunce's appointment follows the resignation of the city's previous choice, Scott Fisher, who left the…

1 hour ago

Get a 2-Pack of 6.6ft USB Type-C Cables for $5.99

USB Type-C has become the standard for charging and data cables alike, so it's good…

1 hour ago

Best Buy’s Excellent Cyberpowerpc Ryzen X3D Radeon RX 9070 XT Gaming PC Deal Ends Tonight

Best Buy is offering an excellent deal on a gaming PC that can comfortably run…

1 hour ago

National Weather Service takes you behind the scenes of predicting severe weather

National Weather Service will be presenting a new seminar series later this month, focusing on…

1 hour ago

Rockford house fire leaves dog dead, homeowner displaced, officials say

The Rockford Fire Department says an afternoon house fire left a dog dead and displaced…

2 hours ago

This website uses cookies.