logo

Zscaler data breach exposes customer info after Salesloft Drift compromise

ID: 8d55adac-54fe-5bf9-acb4-e30e2a2890da

STIX ID: report--8d55adac-54fe-5bf9-acb4-e30e2a2890da

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2025-09-01

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Zscaler disclosed a data breach where attackers used stolen Salesloft Drift credentials to access its Salesforce instance and exfiltrate customer details (names, business emails, job titles, phone numbers, regional info, product licensing/commercial info) and support-case contents. The incident is tied to a broader campaign—attributed by Google to UNC6395—where social-engineering (vishing) and stolen OAuth/refresh tokens were used to access Salesforce and Google Workspace accounts, impacting numerous organizations and prompting revocation of integrations and token rotations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.