Qualys
Disclosed Sep 4, 20251 year agoConfirmed
Qualys Salesforce data stolen via Salesloft Drift OAuth tokens
Qualys said stolen Drift tokens exposed a limited set of Salesforce business records, with no impact on its production platforms, codebase or customer scan data.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 4, 2025 |
| Attack | Supply chain |
| Data exposed | Names, Emails, Other |
| Sector | Tech · US |
| Status | Confirmed |
| Part of | Salesloft drift (2025) |
Sources
| Source | |
|---|---|
| Qualys statement on the Salesloft Drift incidentblog.qualys.com · The organization | The organization |
| Salesloft Drift Breach: Track the Salesforce Incident (Nudge Security)driftbreach.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 4, 2025 |
Same campaign
Other breaches at Qualys
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Qualys customer files taken through Accellion FTA serverMar 4, 20215 years agoSupply chain | Mar 4, 20215 years ago | Supply chain | Tech | Confirmed | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.