Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Palo Alto Networks Confirms Data Breach – Hackers Stole Customer Data from Salesforce Instances

## Cybersecurity Incident: Palo Alto Networks and Salesloft Drift

Cybersecurity Incident: Palo Alto Networks and Salesloft Drift

Palo Alto Networks has confirmed a supply chain attack affecting its Salesforce instances, resulting in unauthorized access to customer data. The breach originated from a compromised third-party application, Salesloft's Drift, without impacting Palo Alto Networks' own products or services.

Upon discovering the incident, Palo Alto Networks immediately disconnected the vendor from its Salesforce environment and initiated a comprehensive investigation conducted by its Unit 42 security team.

The data primarily includes business contact information, internal sales account details, and basic customer case data. A limited number of customers with potentially more sensitive data have been notified. The data breach occurred between August 8 and August 18, 2025, utilizing compromised OAuth tokens to access and exfiltrate data from Salesforce environments.

Other major technology companies, including Zscaler and Google, were also affected. In response, Salesloft and Salesforce revoked all active access tokens for the Drift application and temporarily removed it from the Salesforce AppExchange.

Recommendations for Affected Organizations

Palo Alto Networks' Unit 42 advises organizations using the Salesloft Drift integration to:

Palo Alto Networks has confirmed a supply chain attack affecting its Salesforce instances, resulting in unauthorized access to customer data.
Madison Drake · Thehackingpost

Review Salesforce logs for suspicious activity, especially for the user agent string Python/3.11 aiohttp/3.12.15 . Rotate any credentials or secrets stored in the compromised data. Enhance security measures with Zero Trust principles.

Supply Chain Attack: Salesloft Drift OAuth Tokens

In August 2025, the misuse of compromised OAuth tokens associated with Salesloft's Drift application led to unauthorized access to Salesforce environments. The attack targeted hundreds of organizations, focusing on credential harvesting and data exfiltration.

Palo Alto Networks: Exposure of business contact information and internal sales data. Zscaler: Customer information, including names and contact details, was accessed. Google: A small number of Workspace accounts were accessed.

Advertisement

"ShinyHunters" Salesforce Social Engineering Campaign

A separate campaign by the group "ShinyHunters" has targeted major corporations using voice phishing tactics. This approach involves impersonating IT support to gain access to Salesforce instances.

Google: Accessed Salesforce system containing Google Ads customer information. Major Brands: Targeted companies include LVMH, Chanel, and Adidas. Financial and Insurance: Affected companies include Allianz Life, Farmers Insurance, and TransUnion, with the latter impacting 4.4 million U.S. consumers.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories