Palo Alto Networks is writing to customers that may have had commercially sensitive data exposed after criminals used stolen OAuth credentials lifted from the Salesloft Drift break-in to gain entry to its Salesforce instance. Marc Benoit, chief information security officer at PAN, confirmed in a note to clients - seen by The Register - that it was informed on August 25 that the “compromise of a third-party application, Salesloft’s Drift, resulted in the access and exfiltration of data stored in our Salesforce environment.” It immediately disconnected the third-party application from its Salesforce CRM, he said. “The investigation [by the Unit 42 team] confirms that the event was isolated to our Salesforce environment and did not affect any Palo Alto Networks products, systems or services.” Benoit said it “further confirmed that the data involved includes primarily customer business contact information, such as names and contact info, company attributes, and basic customer support case information. It is important to note that no tech support files or attachments to any customer support cases were part of the exfiltration.” All PAN products and services “remain secure, fully operational, and safe to use,” he added. “We take this incident seriously, and beyond this notification, we are reaching out to a limited number of customers who may have had commercially sensitive data exposed." The Unit 42 team within PAN are still combing through things, “conducting enhanced, continuous...
Stolen OAuth tokens expose Palo Alto customer data
The Register
·Paul Kunert
·Published Sep 2, 2025
·Updated
Affected Software
2 affected components
Salesloft Drift
Salesforce Salesforce
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a data breach involving stolen OAuth tokens that expose customer data at Palo Alto Networks.
2
What security implications are discussed?
The breach highlights the risks associated with stolen OAuth credentials and their potential to compromise sensitive customer data in connected systems.
3
What products or software are affected?
The affected software includes Salesloft Drift and Salesforce.
4
How did the criminals gain access to Palo Alto Networks' data?
Criminals gained access by using stolen OAuth credentials obtained from a previous break-in at Salesloft.
5
What actions is Palo Alto Networks taking in response to the breach?
Palo Alto Networks is informing affected customers about the potential exposure of their commercially sensitive data.