Elastic
Disclosed Sep 4, 20251 year agoConfirmed
Elastic Salesforce data stolen via Salesloft Drift OAuth tokens
Elastic said its Salesforce environment was not affected but one email account connected through the Drift Email integration was exposed, giving read access to inbound emails, a few of which contained valid credentials that it rotated.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 4, 2025 |
| Attack | Supply chain |
| Data exposed | Emails, Credentials and tokens |
| Sector | Tech · US |
| Status | Confirmed |
| Part of | Salesloft drift (2025) |
Sources
| Source | |
|---|---|
| Salesloft Drift Breach: Track the Salesforce Incident (Nudge Security)driftbreach.com · News | News |
| Elastic statement on the Salesloft Drift incidentelastic.co · The organization | The organization |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 4, 2025 |
Same campaign
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.