Esker
Disclosed Sep 1, 20251 year agoConfirmed
Esker Salesforce data stolen via Salesloft Drift OAuth tokens
Esker said stolen OAuth credentials were used between August 8 and 18, 2025 to access its Salesforce support case content, including names, business emails, job titles, phone numbers and ticket text.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 1, 2025 |
| Attack | Supply chain |
| Data exposed | Names, Emails, Phone numbers, Employment, Other |
| Sector | Tech · FR |
| Status | Confirmed |
| Part of | Salesloft drift (2025) |
Sources
| Source | |
|---|---|
| Salesloft Drift Breach: Track the Salesforce Incident (Nudge Security)driftbreach.com · News | News |
| Esker statement on the Salesloft Drift incidentesker.com · The organization | The organization |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 1, 2025 |
Same campaign
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.