No Result
View All Result
SUBMIT YOUR ARTICLES
  • Login
Sunday, May 3, 2026
TheAdviserMagazine.com
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal
No Result
View All Result
TheAdviserMagazine.com
No Result
View All Result
Home Market Research Market Analysis

The Abyss Of The Salesloft-Salesforce Breach May Reach The Challenger Deep

by TheAdviserMagazine
8 months ago
in Market Analysis
Reading Time: 3 mins read
A A
The Abyss Of The Salesloft-Salesforce Breach May Reach The Challenger Deep
Share on FacebookShare on TwitterShare on LInkedIn


News has been trickling out since August 20 about a security issue in Salesloft’s Drift product, a marketing and sales chatbot that integrates with CRM systems to capture and track sales opportunities. The issue started in March, when threat actors accessed Salesloft’s GitHub account and did reconnaissance, which helped them access Drift’s AWS environment and obtain OAuth tokens. From there, they accessed Drift customers’ Salesforce instances from August 8–18.

Salesforce has suffered repeated attacks this year where advanced persistent threats (APTs) compromised customer databases by targeting individual companies. This attack is much broader in terms of both scope and number of companies affected, as Drift is a popular tool used by over 700 companies. Its customers include several notable cybersecurity vendors such as Black Duck, Cloudflare, Okta, OneTrust, Palo Alto Networks, Proofpoint, and Zscaler.

What Data Was Compromised?

By design, Drift is meant to improve sales engagement with prospects and customers. Its integration with CRM systems lets Drift track leads, update CRM records, and trigger follow-up actions. Because of the Salesforce integration, the threat actors were able to access:

Sensitive information about client environments such as IP addresses, account information, and access tokens. These are stored in clear text within support case notes to make supporting that customer easier when a case is passed to multiple analysts, but for a hacker, this gives them critical access details to the client’s infrastructure.
Standard information about accounts such as client contact data, sales pipeline, support history, and business strategy. This information seems generic, but for social engineering campaigns, these are the details that threat actors need to make their engagement more believable.

Actions To Take Now To Reduce The Threat To Your Business

While Salesloft has reset the authentication tokens and temporarily disabled Drift, impacted businesses need to take further steps to protect themselves and their employees. After working with their third-party risk management program to define the scope of the breach, companies should take the following actions:

Revoke and rotate all API keys, credentials, and authentication tokens associated with the integration. Additionally, if your investigation of your Salesforce data uncovers any hardcoded secrets or exposed API keys/credentials, they must be rotated immediately. Establish a regular rotation schedule for all API keys and other secrets used in third-party integrations to reduce the window of exposure.
Tune tech and train teams for the social engineering onslaught. Various human-element breach types and tactics will spring up in the coming weeks and months based on the data that was extracted, requiring specific tech and process controls. Your email, messaging, and collaboration security solution and your employees should be tuned to spot the traditional signs of social engineering: authority, novelty, and urgency. Employees should be encouraged — and publicly praised — to pause in the face of these signs and seek additional verification before providing information or completing transactions.
Institute least privileged access controls on your data used by third parties. The guidance we’ve provided on SaaS security applies equally to app developers and customers to limit access to data to only what is needed for that function to execute. In this campaign, companies that restricted inbound access from approved IP addresses did not have their Salesforce data extracted, even though they were targeted. Utilize SaaS security posture management solutions to uncover the risks in your SaaS deployments and improve threat monitoring of your configurations within these apps to limit your exposure based on identified risks.
Secure your software supply chain. Start with an inventory of all software used in the development and delivery process; this includes open-source software tools and components. Ensure that dev environments, pipelines, and source-code management systems utilize Zero Trust principles, have phishing-resistant multifactor authentication enforced, enable branch protection, monitor for security misconfigurations, automate application security testing, and utilize a secrets management solution to avoid any credentials, tokens, or environment variables being passed in plaintext.
Define your incident escalation matrix. Delineate severity levels and assess materiality in the context of the regulatory requirements to which your organization is beholden. Socialize this matrix with all internal and external stakeholders, and work with outside counsel and your incident response service provider to develop executive and board tabletop exercises involving complex, cascading nth-party breach and breach notification scenarios.

Stay Tuned

Details continue to emerge from Salesloft as well as businesses directly impacted by the breach. Because we still don’t know how many companies were victims of data theft or the exact attack details, the total impact remains unclear. The security and risk team at Forrester will provide updates to help clients as new details come to light.



Source link

Tags: AbyssBreachchallengerDeepreachSalesloftSalesforce
ShareTweetShare
Previous Post

Microsoft: Startet jetzt der Angriff auf das Rekordhoch?

Next Post

Important takeaways from Adobe’s (ADBE) Q3 2025 earnings report

Related Posts

edit post
Through-Channel Marketing Automation (TCMA): The 2026 Guide to Scaling Partner Demand

Through-Channel Marketing Automation (TCMA): The 2026 Guide to Scaling Partner Demand

by TheAdviserMagazine
May 2, 2026
0

While 50% of brands have invested in a through-channel marketing automation tcma platform, a staggering 83% of those organizations feel...

edit post
Lead Distribution Automation Software: The 2026 Guide to Indirect Sales Efficiency

Lead Distribution Automation Software: The 2026 Guide to Indirect Sales Efficiency

by TheAdviserMagazine
May 1, 2026
0

If 80% of automation users are generating more leads, why are so many manufacturers still watching high-value opportunities wither away...

edit post
SUSECON 2026: From Open Infrastructure To Operational Sovereignty

SUSECON 2026: From Open Infrastructure To Operational Sovereignty

by TheAdviserMagazine
May 1, 2026
0

SUSECON 2026 in Prague marked a clear advance on the platform pillars SUSE introduced a year earlier in Orlando —...

edit post
Atlassian And ServiceNow: The Dominant AI-Enabled IT Management Platforms Lean Into Context Graphs

Atlassian And ServiceNow: The Dominant AI-Enabled IT Management Platforms Lean Into Context Graphs

by TheAdviserMagazine
May 1, 2026
0

A two-years-later follow-up to ServiceNow And Atlassian: The Rise Of IT Management Platforms (July 2024) and a continuation of Context...

edit post
3 Software Stocks to Buy on the Dip With Accelerating AI-Driven Earnings Growth

3 Software Stocks to Buy on the Dip With Accelerating AI-Driven Earnings Growth

by TheAdviserMagazine
May 1, 2026
0

Salesforce, Adobe, and HubSpot have all suffered bruising year-to-date stock price declines. Despite the drawdown, each offers double-digit revenue growth,...

edit post
9 High Cash Flow Stocks Likely to Outperform If Rates Stay Higher for Longer

9 High Cash Flow Stocks Likely to Outperform If Rates Stay Higher for Longer

by TheAdviserMagazine
April 30, 2026
0

The Fed has made it clear that rate cuts are not coming anytime soon. Some companies, however, can actually hold...

Next Post
edit post
Important takeaways from Adobe’s (ADBE) Q3 2025 earnings report

Important takeaways from Adobe’s (ADBE) Q3 2025 earnings report

edit post
44% of People With This Debilitating Disease Don’t Know They Have It

44% of People With This Debilitating Disease Don’t Know They Have It

  • Trending
  • Comments
  • Latest
edit post
Florida Warning: With Senior SNAP Benefits Averaging 8/Month, Thousands Risk Losing Assistance in 2026

Florida Warning: With Senior SNAP Benefits Averaging $188/Month, Thousands Risk Losing Assistance in 2026

April 27, 2026
edit post
Tax Flight Accelerates In Massachusetts

Tax Flight Accelerates In Massachusetts

April 6, 2026
edit post
The Stevia Loophole Why Some Sweetened Drinks are Still SNAP-Legal While Others are Banned in Texas

The Stevia Loophole Why Some Sweetened Drinks are Still SNAP-Legal While Others are Banned in Texas

April 4, 2026
edit post
10 Cheapest High Dividend Stocks With P/E Ratios Under 10

10 Cheapest High Dividend Stocks With P/E Ratios Under 10

April 13, 2026
edit post
Exclusive: America’s largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth

Exclusive: America’s largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth

April 29, 2026
edit post
I Replaced My K Salary with 2 Real Estate Deals Per Year

I Replaced My $80K Salary with 2 Real Estate Deals Per Year

April 6, 2026
edit post
3 Altcoins Eyeing Rebounds With Key Resistance Zones in Sight

3 Altcoins Eyeing Rebounds With Key Resistance Zones in Sight

0
edit post
HELOC and home equity loan rates Sunday, May 3, 2026: Lenders doing more to compete for your home equity business

HELOC and home equity loan rates Sunday, May 3, 2026: Lenders doing more to compete for your home equity business

0
edit post
Portugal’s Defense Sector Rising | Armstrong Economics

Portugal’s Defense Sector Rising | Armstrong Economics

0
edit post
Adults Over 55 Getting Less Than 6 Hours of Sleep Could Face Faster Memory Decline

Adults Over 55 Getting Less Than 6 Hours of Sleep Could Face Faster Memory Decline

0
edit post
Israel orders southern Lebanon evacuations amid military operations

Israel orders southern Lebanon evacuations amid military operations

0
edit post
10 Largecap stocks with strong upside potential of up to 50%! Do you own any? – Largecap stocks surge

10 Largecap stocks with strong upside potential of up to 50%! Do you own any? – Largecap stocks surge

0
edit post
HELOC and home equity loan rates Sunday, May 3, 2026: Lenders doing more to compete for your home equity business

HELOC and home equity loan rates Sunday, May 3, 2026: Lenders doing more to compete for your home equity business

May 3, 2026
edit post
Israel orders southern Lebanon evacuations amid military operations

Israel orders southern Lebanon evacuations amid military operations

May 3, 2026
edit post
Zoom is handing 0K to solopreneurs as AI pushes 33 million workers to become their own boss

Zoom is handing $150K to solopreneurs as AI pushes 33 million workers to become their own boss

May 3, 2026
edit post
10 Largecap stocks with strong upside potential of up to 50%! Do you own any? – Largecap stocks surge

10 Largecap stocks with strong upside potential of up to 50%! Do you own any? – Largecap stocks surge

May 3, 2026
edit post
This Week In Bitcoin: Top Developments That Could Signal A New Era

This Week In Bitcoin: Top Developments That Could Signal A New Era

May 3, 2026
edit post
What 40 years of showing up to hard, physical work taught me about the mental habits no productivity app will ever replicate

What 40 years of showing up to hard, physical work taught me about the mental habits no productivity app will ever replicate

May 2, 2026
The Adviser Magazine

The first and only national digital and print magazine that connects individuals, families, and businesses to Fee-Only financial advisers, accountants, attorneys and college guidance counselors.

CATEGORIES

  • 401k Plans
  • Business
  • College
  • Cryptocurrency
  • Economy
  • Estate Plans
  • Financial Planning
  • Investing
  • IRS & Taxes
  • Legal
  • Market Analysis
  • Markets
  • Medicare
  • Money
  • Personal Finance
  • Social Security
  • Startups
  • Stock Market
  • Trading

LATEST UPDATES

  • HELOC and home equity loan rates Sunday, May 3, 2026: Lenders doing more to compete for your home equity business
  • Israel orders southern Lebanon evacuations amid military operations
  • Zoom is handing $150K to solopreneurs as AI pushes 33 million workers to become their own boss
  • Our Great Privacy Policy
  • Terms of Use, Legal Notices & Disclosures
  • Contact us
  • About Us

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Financial Planning
    • Financial Planning
    • Personal Finance
  • Market Research
    • Business
    • Investing
    • Money
    • Economy
    • Markets
    • Stocks
    • Trading
  • 401k Plans
  • College
  • IRS & Taxes
  • Estate Plans
  • Social Security
  • Medicare
  • Legal

© Copyright 2024 All Rights Reserved
See articles for original source and related links to external sites.