Zscaler latest victim of Salesloft Drift attacks, customer data exposed
ID: d744746d-9d5f-5d60-a273-c123d3539063
STIX ID: report--d744746d-9d5f-5d60-a273-c123d3539063
Feed Name: The Register (Security)
Zscaler disclosed that limited Salesforce-related customer data was exposed after OAuth tokens were stolen from Salesloft Drift integrations between August 8–18; the activity, suspected to be carried out by a group linked to ShinyHunters (UNC6395), resulted in mass exfiltration from Salesforce objects affecting multiple vendors and customers (including Zscaler, Google Workspace accounts, and Palo Alto Networks' customers). Organizations are advised to revoke Drift access, rotate API tokens, and review login and API access logs from August 8 onward.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
