PagerDuty
Disclosed Sep 4, 20251 year agoConfirmed
PagerDuty Salesforce data stolen via Salesloft Drift OAuth tokens
PagerDuty said it was informed on August 23, 2025 that a threat actor may have accessed its Salesforce instance through the compromised Drift authorization flow.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 4, 2025 |
| Discovered | Aug 23, 2025 |
| Attack | Supply chain |
| Data exposed | Names, Emails, Other |
| Sector | Tech · US |
| Status | Confirmed |
| Part of | Salesloft drift (2025) |
Sources
| Source | |
|---|---|
| Salesloft Drift Breach: Track the Salesforce Incident (Nudge Security)driftbreach.com · News | News |
| PagerDuty statement on the Salesloft Drift incidentpagerduty.com · The organization | The organization |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 4, 2025 |
Same campaign
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.