logo

Cloudflare hit by data breach in Salesloft Drift supply chain attack

ID: e2fa63f3-7064-5700-ac6e-3db0cac5cca5

STIX ID: report--e2fa63f3-7064-5700-ac6e-3db0cac5cca5

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-09-02

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Cloudflare disclosed that attackers accessed a Salesforce instance via the Salesloft/Drift supply-chain compromise and exfiltrated 104 Cloudflare-issued API tokens and text-based support case contents (subject lines, case bodies, and customer contact information) between August 12–17; the company rotated the impacted tokens and warned customers to rotate any credentials shared in support tickets. The incident is part of a wider wave of Salesforce-targeting breaches linked to social-engineering campaigns (including activity attributed to ShinyHunters) affecting many organizations and raising the risk of targeted follow-on attacks and extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.