Palo Alto Networks
Disclosed Sep 2, 20251 year agoConfirmed
Palo Alto Networks Salesforce data stolen via Salesloft Drift OAuth tokens
Palo Alto Networks confirmed attackers used compromised Drift OAuth tokens to access its Salesforce instance and exfiltrate customer contact data and support case information.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 2, 2025 |
| Attack | Supply chain |
| Data exposed | Names, Emails, Phone numbers, Other |
| Sector | Tech · US |
| Status | Confirmed |
| Part of | Salesloft drift (2025) |
Sources
| Source | |
|---|---|
| Palo Alto Networks data breach exposes customer info, support casesbleepingcomputer.com · News | News |
| Salesloft Drift Breach: Track the Salesforce Incident (Nudge Security)driftbreach.com · News | News |
| Palo Alto Networks statement on the Salesloft Drift incidentpaloaltonetworks.com · The organization | The organization |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 2, 2025 |
Same campaign
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.