Cloudflare is the latest company impacted in a recent string of Salesloft Drift breaches, part of a supply-chain attack disclosed last week. The internet giant revealed on Tuesday that the attackers gained access to a Salesforce instance it uses for internal customer case management and customer support, which contained 104 Cloudflare API tokens. Cloudflare was notified of the breach on August 23, and it alerted impacted customers of the incident on September 2. Before informing customers of the attack, it also rotated all 104 Cloudflare platform-issued tokens exfiltrated during the breach, even though it has yet to discover any suspicious activity linked to these tokens. "Most of this information is customer contact information and basic support case data, but some customer support interactions may reveal information about a customer's configuration and could contain sensitive information like access tokens," Cloudflare said. "Given that Salesforce support case data contains the contents of support tickets with Cloudflare, any information that a customer may have shared with Cloudflare in our support system—including logs, tokens or passwords—should be considered compromised, and we strongly urge you to rotate any credentials that you may have shared with us through this channel." The company's investigation found that the threat actors stole only the text contained within the Salesforce case objects (including customer support tickets and their associated data, but no atta...
Cloudflare hit by data breach in Salesloft Drift supply chain attack
BleepingComputer
·Sergiu Gatlan
·Published Sep 2, 2025
·Updated
Affected Software
2 affected components
Salesforce Salesforce
Cloudflare Cloudflare
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a data breach affecting Cloudflare due to a supply chain attack involving Salesloft and Drift.
2
What security implications are discussed in the article?
The article highlights the risks of supply chain attacks and the potential exposure of sensitive data due to third-party vulnerabilities.
3
What companies are involved in this breach?
The breach involves Cloudflare, Salesloft, and Drift, with an emphasis on the Salesforce integration.
4
What products or software are affected by this breach?
The affected products include Cloudflare services and Salesforce.
5
When was this breach disclosed?
The breach was disclosed on Tuesday, following the recent string of Supplyloft Drift attacks.