• News/
  • https://www.bleepingcomputer.com/news/security/zscaler-data-breach-exposes-customer-info-after-salesloft-drift-compromise/

Zscaler data breach exposes customer info after Salesloft Drift compromise

BleepingComputer
·
Lawrence Abrams
·
Published Sep 1, 2025
·
Updated

Cybersecurity company Zscaler warns it suffered a data breach after threat actors gained access to its Salesforce instance and stole customer information, including the contents of support cases. This warning follows the compromise of Salesloft Drift, an AI chat agent that integrates with Salesforce, in which attackers stole OAuth and refresh tokens, enabling them to gain access to customer Salesforce environments and exfiltrate sensitive data. In an advisory, Zscaler says that its Salesforce instance was impacted by this supply-chain attack, exposing customers' information. "As part of this campaign, unauthorized actors gained access to Salesloft Drift credentials of its customers including Zscaler," reads Zscaler's advisory. "Following a detailed review as part of our ongoing investigation, we have determined that these credentials have allowed limited access to some Zscaler's Salesforce information." After publishing this story, Zscaler told BleepingComputer that data exfiltration occurred between August 13 to 16th, with the data accessed a few other times prior to then. The exposed information includes the following: The breach impacts a large number of customers but Zscaler is not sharing the total number. The company stresses that the data breach only impacts its Salesforce instance and no Zscaler products, services, or infrastructure. While Zscaler states that it has detected no misuse of this information, it recommends that customers remain vigilant against potential...

Read full article

Affected Software

2 affected components
Salesforce Salesforce
Salesloft Drift
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a data breach experienced by Zscaler that exposed customer information due to a compromise in their Salesforce instance.

2

What security implications are discussed?

The breach raises concerns about the security of customer data and the potential risks associated with third-party integrations.

3

What products or software are affected?

The affected products include Salesforce and Salesloft's Drift.

4

How did the data breach occur?

The breach occurred after threat actors gained unauthorized access to Zscaler's Salesforce instance.

5

What type of customer information was exposed in the breach?

The exposed information includes the contents of support cases and other customer-related data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203