CyberArk
Disclosed Sep 4, 20251 year agoUnverified
CyberArk Salesforce data stolen via Salesloft Drift OAuth tokens
CyberArk confirmed attackers used compromised Drift OAuth tokens to access its Salesforce CRM data, limited to business contact details, account and conversation metadata.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 4, 2025 |
| Attack | Supply chain |
| Data exposed | Names, Emails, Other |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
| Part of | Salesloft drift (2025) |
Sources
| Source | |
|---|---|
| SaaS giant Workiva discloses data breach after Salesforce attackbleepingcomputer.com · News | News |
| Salesloft Drift Breach: Track the Salesforce Incident (Nudge Security)driftbreach.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 4, 2025 |
Same campaign
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.