Palo Alto Networks Confirms Data Breach – Hackers Stole Customer Data from Salesforce Instances
## Cybersecurity Incident: Palo Alto Networks and Salesloft Drift
Cybersecurity Incident: Palo Alto Networks and Salesloft Drift
Palo Alto Networks has confirmed a supply chain attack affecting its Salesforce instances, resulting in unauthorized access to customer data. The breach originated from a compromised third-party application, Salesloft's Drift, without impacting Palo Alto Networks' own products or services.
Upon discovering the incident, Palo Alto Networks immediately disconnected the vendor from its Salesforce environment and initiated a comprehensive investigation conducted by its Unit 42 security team.
The data primarily includes business contact information, internal sales account details, and basic customer case data. A limited number of customers with potentially more sensitive data have been notified. The data breach occurred between August 8 and August 18, 2025, utilizing compromised OAuth tokens to access and exfiltrate data from Salesforce environments.
Other major technology companies, including Zscaler and Google, were also affected. In response, Salesloft and Salesforce revoked all active access tokens for the Drift application and temporarily removed it from the Salesforce AppExchange.
Recommendations for Affected Organizations
Palo Alto Networks' Unit 42 advises organizations using the Salesloft Drift integration to:
Palo Alto Networks has confirmed a supply chain attack affecting its Salesforce instances, resulting in unauthorized access to customer data.
Review Salesforce logs for suspicious activity, especially for the user agent string Python/3.11 aiohttp/3.12.15 . Rotate any credentials or secrets stored in the compromised data. Enhance security measures with Zero Trust principles.
Supply Chain Attack: Salesloft Drift OAuth Tokens
In August 2025, the misuse of compromised OAuth tokens associated with Salesloft's Drift application led to unauthorized access to Salesforce environments. The attack targeted hundreds of organizations, focusing on credential harvesting and data exfiltration.
Palo Alto Networks: Exposure of business contact information and internal sales data. Zscaler: Customer information, including names and contact details, was accessed. Google: A small number of Workspace accounts were accessed.
"ShinyHunters" Salesforce Social Engineering Campaign
A separate campaign by the group "ShinyHunters" has targeted major corporations using voice phishing tactics. This approach involves impersonating IT support to gain access to Salesforce instances.
Google: Accessed Salesforce system containing Google Ads customer information. Major Brands: Targeted companies include LVMH, Chanel, and Adidas. Financial and Insurance: Affected companies include Allianz Life, Farmers Insurance, and TransUnion, with the latter impacting 4.4 million U.S. consumers.
Based on reporting by Cyber Security News.
