Zscaler data breach exposes customer info after Salesloft Drift compromise
ID: 8d55adac-54fe-5bf9-acb4-e30e2a2890da
STIX ID: report--8d55adac-54fe-5bf9-acb4-e30e2a2890da
Feed Name: Bleeping Computer
Zscaler disclosed a data breach where attackers used stolen Salesloft Drift credentials to access its Salesforce instance and exfiltrate customer details (names, business emails, job titles, phone numbers, regional info, product licensing/commercial info) and support-case contents. The incident is tied to a broader campaign—attributed by Google to UNC6395—where social-engineering (vishing) and stolen OAuth/refresh tokens were used to access Salesforce and Google Workspace accounts, impacting numerous organizations and prompting revocation of integrations and token rotations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
