PagerDuty Confirms Data Breach After Salesforce Account Compromise
PagerDuty has confirmed a data breach following a compromise of its Salesforce account.
PagerDuty has confirmed a data breach following a compromise of its Salesforce account.
The issue was first reported by Salesloft on Sun, Aug 20, 2025, when they notified PagerDuty of a security problem within the Drift application.
On Wed, Aug 23, 2025, Salesloft disclosed that attackers had exploited a vulnerability in Drift’s OAuth integration flow with Salesforce.
This unauthorized authorization process potentially allowed threat actors access to PagerDuty’s Salesforce account. However, no PagerDuty credentials, such as usernames or passwords, were exposed during the incident.
On Sun, Aug 27, 2025, Salesloft recommended additional precautions for customers managing their own Drift connections to third-party applications.
In response, PagerDuty has disabled Salesloft Drift’s access to its Salesforce data and is actively investigating the incident.
Currently, PagerDuty has found no evidence of access to its platform, internal systems, or any resources beyond Salesforce.
PagerDuty has confirmed a data breach following a compromise of its Salesforce account.
Nevertheless, due to possible exposure of names, phone numbers, and email addresses stored in Salesforce, PagerDuty advises all customers and contacts to remain vigilant.
The company warns of an increased risk of phishing and social engineering attacks and emphasizes that it will never request passwords or secure details via phone. All official communications from PagerDuty are conducted through recognized support channels.
The technical details and background of the security issue have been shared by Salesloft, Salesforce, and the Google Threat Intelligence Group.
PagerDuty is adhering to guidance from these entities and will implement any additional measures necessary to protect customer data.
The company is committed to keeping customers informed of new developments and providing clear guidance as the investigation continues.
PagerDuty remains dedicated to the security and privacy of its customers. The company is reviewing its security controls and collaborating with Salesloft to enhance the OAuth integration process.
Updates and recommendations will be provided as they become available.
For additional information on the Salesloft Drift security update, please visit the Salesloft Trust site, the Salesforce status page, or the Google Cloud blog post from the Threat Intelligence Group.
PagerDuty appreciates its customers’ understanding and cooperation as the company works to resolve this matter and safeguard customer data.
Based on reporting by GBHackers.
