logo

How big will this Drift get? Cloudflare cops to Salesloft Drift breach

ID: e2f1912f-513b-5875-a66d-c0f5993c819d

STIX ID: report--e2f1912f-513b-5875-a66d-c0f5993c819d

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-09-02

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Cloudflare disclosed that some customer data was exposed after attackers leveraged the Salesloft/Drift breach to access its Salesforce tenant between August 12–17; the company attributes the activity to GRUB1 (tracked as UNC6395), rotated tokens, notified impacted customers, and published timelines, recommendations, and IoCs. Multiple large organizations (Google, Palo Alto Networks, Zscaler and others) were also affected, and Cloudflare warns attackers may reuse harvested credentials for targeted follow-on attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.