Updated Salesforce is facing a wave of lawsuits in the wake of a cyberattack that exposed customer data. The claims were all filed in Northern California, where Salesforce is headquartered, over the past five weeks and suggest that the SaaS CRM vendor fell short on security. The complaints, many of which aim for class action status, allege that the personal information of the complainants stolen in the attack is making them targets for identity theft. Salesforce has denied that the security breaches were a result of any shortcomings in its systems. In its public notices, the company has said that its platform was not compromised. From May through summer, a number of Salesforce-related breaches came to light in which attackers stole OAuth tokens from the third-party Salesloft Drift app. Google Threat Intelligence Group later confirmed the attacks. The Register has viewed 15 filings of cases against Salesforce and its users by individuals including those launching class actions. For example, a suit led by Staci Johnson [PDF] accuses Salesforce of failing to properly secure her personally identifiable information (PII) in connection with a data breach in July 2025. The claim calls for Salesforce to "disclose the nature of the information that has been compromised and to adopt sufficient security practices and safeguards to prevent incidents… in the future." The claim says the breach was a "direct result" of Salesforce's "failure to implement adequate and reasonable cybersecurity...
Salesforce faces class action after Salesloft breach
The Register
·Lindsay Clark
·Published Sep 26, 2025
·Updated
Affected Software
2 affected components
Salesforce Salesforce
Salesloft Drift
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses Salesforce facing multiple class action lawsuits following a cyberattack that compromised customer data.
2
What were the consequences of the Salesloft breach for Salesforce?
Salesforce is experiencing legal challenges as a result of the data exposure linked to the Salesloft breach.
3
Where were the lawsuits against Salesforce filed?
The lawsuits were filed in Northern California, where Salesforce is headquartered.
4
What type of customer data was exposed in the breach?
The article indicates that the cyberattack led to the exposure of sensitive customer data.
5
Which software products are mentioned as affected by the breach?
The affected software products mentioned are Salesforce and Salesloft.