• News/
  • https://www.theregister.com/2025/09/02/cloudflare_salesloft_drift_breach/

How big will this Drift get? Cloudflare cops to Salesloft Drift breach

The Register
·
Jessica Lyons
·
Published Sep 2, 2025
·
Updated

The list of victims keeps growing, as yet another company — Cloudflare — today disclosed that some of its customers' data was also compromised in the Salesloft Drift breach. In a very comprehensive post mortem published Tuesday, Cloudflare's Head of Security Response Sourov Zaman, Senior Director of Threat Detection and Response Craig Strubhart, and Chief Information Security Officer Grant Bourzikas detailed the Drift attack, which affected Salesforce databases. Drift is a third-party app that integrates with Salesforce databases to help manage leads. "Because of this breach, someone outside Cloudflare got access to our Salesforce instance, which we use for customer support and internal customer case management, and some of the data it contains," the Cloudflare trio wrote. "Most of this information is customer contact information and basic support case data, but some customer support interactions may reveal information about a customer's configuration and could contain sensitive information like access tokens," they continued. "Given that Salesforce support case data contains the contents of support tickets with Cloudflare, any information that a customer may have shared with Cloudflare in our support system — including logs, tokens or passwords — should be considered compromised, and we strongly urge you to rotate any credentials that you may have shared with us through this channel." Cloudflare also pinned the blame on a threat group it tracks as GRUB1, which the security e...

Read full article

Affected Software

2 affected components
Salesforce Salesforce
Cloudflare Drift
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a data breach involving Cloudflare related to the Salesloft Drift incident.

2

What security implications are discussed?

The security implications include the compromise of customer data and the growing list of affected companies due to the Drift breach.

3

What companies are mentioned as victims of the breach?

The article specifically mentions Cloudflare and Salesloft as part of the ongoing Drift breach situation.

4

What products or software are affected by this breach?

The affected products include Salesforce and Cloudflare's Drift software.

5

What measures are being taken in response to the breach?

The article outlines a comprehensive post mortem analysis by Cloudflare in response to the breach.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203