• News/
  • https://www.theregister.com/2025/09/02/stolen_oauth_tokens_expose_palo/

Stolen OAuth tokens expose Palo Alto customer data

The Register
·
Paul Kunert
·
Published Sep 2, 2025
·
Updated

Palo Alto Networks is writing to customers that may have had commercially sensitive data exposed after criminals used stolen OAuth credentials lifted from the Salesloft Drift break-in to gain entry to its Salesforce instance. Marc Benoit, chief information security officer at PAN, confirmed in a note to clients - seen by The Register - that it was informed on August 25 that the “compromise of a third-party application, Salesloft’s Drift, resulted in the access and exfiltration of data stored in our Salesforce environment.” It immediately disconnected the third-party application from its Salesforce CRM, he said. “The investigation [by the Unit 42 team] confirms that the event was isolated to our Salesforce environment and did not affect any Palo Alto Networks products, systems or services.” Benoit said it “further confirmed that the data involved includes primarily customer business contact information, such as names and contact info, company attributes, and basic customer support case information. It is important to note that no tech support files or attachments to any customer support cases were part of the exfiltration.” All PAN products and services “remain secure, fully operational, and safe to use,” he added. “We take this incident seriously, and beyond this notification, we are reaching out to a limited number of customers who may have had commercially sensitive data exposed." The Unit 42 team within PAN are still combing through things, “conducting enhanced, continuous...

Read full article

Affected Software

2 affected components
Salesloft Drift
Salesforce Salesforce
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a data breach involving stolen OAuth tokens that expose customer data at Palo Alto Networks.

2

What security implications are discussed?

The breach highlights the risks associated with stolen OAuth credentials and their potential to compromise sensitive customer data in connected systems.

3

What products or software are affected?

The affected software includes Salesloft Drift and Salesforce.

4

How did the criminals gain access to Palo Alto Networks' data?

Criminals gained access by using stolen OAuth credentials obtained from a previous break-in at Salesloft.

5

What actions is Palo Alto Networks taking in response to the breach?

Palo Alto Networks is informing affected customers about the potential exposure of their commercially sensitive data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203