Palo Alto Networks Confirms Data Breach via Compromised Salesforce Instances
Palo Alto Networks has reported a security incident involving its Salesforce environment, caused by a compromised Salesloft Drift integration. This incident is part of a series of supply chain attacks focusing on customer relationship management…
Palo Alto Networks has reported a security incident involving its Salesforce environment, caused by a compromised Salesloft Drift integration. This incident is part of a series of supply chain attacks focusing on customer relationship management platforms.
Salesloft's Drift application, which is widely used for sales engagement, experienced an intrusion affecting OAuth credentials from August 8 to 18, 2025. Unauthorized actors exploited these credentials to access data from connected Salesforce instances, including that of Palo Alto Networks, before Salesloft revoked the tokens and secured the systems.
Palo Alto Networks promptly disconnected the vendor from its Salesforce environment and initiated a comprehensive investigation by its Unit 42 security teams. The investigation confirmed that the compromise was restricted to the CRM platform, with no impact on other Palo Alto Networks products or services.
The breached data mainly included business contact information, internal sales account details, and basic case records. A limited number of customers with potentially more sensitive data exposure are being notified directly through official support channels.
Palo Alto Networks has reported a security incident involving its Salesforce environment, caused by a compromised Salesloft Drift integration.
Salesloft has informed all affected customers and has revoked all active access and refresh tokens for the Drift application, requiring administrators to re-authenticate. Palo Alto Networks advises organizations using the Drift integration to stay vigilant and follow these key recommendations:
Comprehensive log review: Analyze Salesforce login histories, audit trails, API access logs, and UniqueQuery events from August 8 to the present. Look for unusual user-agent strings and suspicious IP addresses. Credential rotation: Use tools like Trufflehog or GitLeaks to identify exposed secrets and promptly rotate compromised credentials, including Salesforce API keys. Network and IdP monitoring: Review network flow and proxy logs for anomalous connections to Salesforce and check identity provider logs for unauthorized authentication attempts.
Organizations are encouraged to adopt zero trust principles to limit access and mitigate risks. Official channels should be used to verify requests for sensitive data.
Palo Alto Networks and Unit 42 continue to monitor the situation and will provide updates as new information becomes available. Salesforce is also offering ongoing guidance and resources to affected customers.
Based on reporting by GBHackers.
