Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Palo Alto Networks Confirms Data Breach via Compromised Salesforce Instances

Palo Alto Networks has reported a security incident involving its Salesforce environment, caused by a compromised Salesloft Drift integration. This incident is part of a series of supply chain attacks focusing on customer relationship management…

Palo Alto Networks has reported a security incident involving its Salesforce environment, caused by a compromised Salesloft Drift integration. This incident is part of a series of supply chain attacks focusing on customer relationship management platforms.

Salesloft's Drift application, which is widely used for sales engagement, experienced an intrusion affecting OAuth credentials from August 8 to 18, 2025. Unauthorized actors exploited these credentials to access data from connected Salesforce instances, including that of Palo Alto Networks, before Salesloft revoked the tokens and secured the systems.

Palo Alto Networks promptly disconnected the vendor from its Salesforce environment and initiated a comprehensive investigation by its Unit 42 security teams. The investigation confirmed that the compromise was restricted to the CRM platform, with no impact on other Palo Alto Networks products or services.

The breached data mainly included business contact information, internal sales account details, and basic case records. A limited number of customers with potentially more sensitive data exposure are being notified directly through official support channels.

Palo Alto Networks has reported a security incident involving its Salesforce environment, caused by a compromised Salesloft Drift integration.
Anna Fields · Thehackingpost

Salesloft has informed all affected customers and has revoked all active access and refresh tokens for the Drift application, requiring administrators to re-authenticate. Palo Alto Networks advises organizations using the Drift integration to stay vigilant and follow these key recommendations:

Comprehensive log review: Analyze Salesforce login histories, audit trails, API access logs, and UniqueQuery events from August 8 to the present. Look for unusual user-agent strings and suspicious IP addresses. Credential rotation: Use tools like Trufflehog or GitLeaks to identify exposed secrets and promptly rotate compromised credentials, including Salesforce API keys. Network and IdP monitoring: Review network flow and proxy logs for anomalous connections to Salesforce and check identity provider logs for unauthorized authentication attempts.

Organizations are encouraged to adopt zero trust principles to limit access and mitigate risks. Official channels should be used to verify requests for sensitive data.

Advertisement

Palo Alto Networks and Unit 42 continue to monitor the situation and will provide updates as new information becomes available. Salesforce is also offering ongoing guidance and resources to affected customers.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories