Toast
Disclosed Sep 18, 20251 year agoConfirmed
Toast Salesforce data stolen via Salesloft Drift OAuth tokens
Toast said a threat actor used stolen Salesloft credentials to query its Salesforce environment between August 12 and 15, 2025, taking customer contact data, support case content and sales configuration data.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Sep 18, 2025 |
| Discovered | Aug 26, 2025 |
| Attack | Supply chain |
| Data exposed | Names, Emails, Addresses, Other |
| Sector | Tech · US |
| Status | Confirmed |
| Part of | Salesloft drift (2025) |
Sources
| Source | |
|---|---|
| Toast statement on the Salesloft Drift incidentupdates.toasttab.com · The organization | The organization |
| Salesloft Drift Breach: Track the Salesforce Incident (Nudge Security)driftbreach.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Sep 18, 2025 |
Same campaign
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.