logo

Stolen OAuth tokens expose Palo Alto customer data

ID: 773bbd94-3e2b-5d56-9b45-2bf6b1383af5

STIX ID: report--773bbd94-3e2b-5d56-9b45-2bf6b1383af5

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-09-02

Date Updated: 2026-04-26

Author: Paul Kunert

...
...

Palo Alto Networks disclosed that attackers leveraged stolen OAuth credentials from the Salesloft/Drift breach to access and exfiltrate customer business contact data from its Salesforce instance; the company isolated the incident to CRM data, disconnected the third-party integration, and Unit 42 recommends token revocation and auditing Salesforce, Salesloft, identity provider, and API logs while performing enhanced monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.