Pantheon
Disclosed Sep 5, 20251 year agoConfirmed
Pantheon Salesforce data stolen via Salesloft Drift OAuth tokens
Pantheon said attackers accessed its Salesforce CRM through the Drift integration between August 12 and 15, 2025, taking customer renewal information, internal sales account data and some contact details.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 5, 2025 |
| Discovered | Aug 28, 2025 |
| Attack | Supply chain |
| Data exposed | Names, Emails, Other |
| Sector | Tech · US |
| Status | Confirmed |
| Part of | Salesloft drift (2025) |
Sources
| Source | |
|---|---|
| Pantheon statement on the Salesloft Drift incidentstatus.pantheon.io · The organization | The organization |
| Salesloft Drift Breach: Track the Salesforce Incident (Nudge Security)driftbreach.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 5, 2025 |
Same campaign
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.