logo

Zscaler latest victim of Salesloft Drift attacks, customer data exposed

ID: d744746d-9d5f-5d60-a273-c123d3539063

STIX ID: report--d744746d-9d5f-5d60-a273-c123d3539063

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-09-02

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Zscaler disclosed that limited Salesforce-related customer data was exposed after OAuth tokens were stolen from Salesloft Drift integrations between August 8–18; the activity, suspected to be carried out by a group linked to ShinyHunters (UNC6395), resulted in mass exfiltration from Salesforce objects affecting multiple vendors and customers (including Zscaler, Google Workspace accounts, and Palo Alto Networks' customers). Organizations are advised to revoke Drift access, rotate API tokens, and review login and API access logs from August 8 onward.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.