{"id":6766,"date":"2025-09-09T10:03:58","date_gmt":"2025-09-09T10:03:58","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/09\/dynatrace-confirms-data-breach-hackers-accessed-customer-data-from-salesforce\/"},"modified":"2025-09-09T10:03:58","modified_gmt":"2025-09-09T10:03:58","slug":"dynatrace-confirms-data-breach-hackers-accessed-customer-data-from-salesforce","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/09\/dynatrace-confirms-data-breach-hackers-accessed-customer-data-from-salesforce\/","title":{"rendered":"Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce"},"content":{"rendered":"<p>    Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Dynatrace has confirmed it was impacted by a third-party data breach originating from the <a href=\"https:\/\/cybersecuritynews.com\/salesloft-drift-cyberattack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Salesloft Drift<\/a> application, resulting in unauthorized access to customer business contact information stored in its Salesforce CRM.<\/p>\n<p>The company confirmed that the incident was limited to its CRM platform and did not impact any core Dynatrace products, services, or sensitive customer environments.<\/p>\n<p>The security incident originated in August 2025, when threat actors compromised Salesloft\u2019s Drift application, a popular third-party tool used for customer engagement. <\/p>\n<p>This compromise allowed the attackers to gain unauthorized access to the Salesforce environments of companies utilizing the app. <\/p>\n<p>In response to the attack, Salesloft and <a href=\"https:\/\/cybersecuritynews.com\/shinyhunters-breaches\/\" target=\"_blank\" rel=\"noreferrer noopener\">Salesforce<\/a> moved to disable the compromised connections and began notifying affected clients, which included the observability giant Dynatrace.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-dynatrace-s-response-and-investigation\"><strong>Dynatrace\u2019s Response And Investigation<\/strong><\/h2>\n<p>Upon receiving notification of the third-party breach, Dynatrace\u2019s security team took immediate action by disabling the Drift application within its environment to sever the connection and prevent further unauthorized access. <\/p>\n<p>The company launched a comprehensive investigation, bringing in third-party cybersecurity experts to determine the full scope of the incident.<\/p>\n<p>The investigation confirmed that the malicious activity was limited exclusively to its Salesforce CRM instance, which the company uses for managing customer relationships and marketing activities. <\/p>\n<p>Critically, Dynatrace <a href=\"https:\/\/www.dynatrace.com\/news\/blog\/salesloft-drift-incident-dynatraces-response\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">clarified<\/a> that none of its own products or services were compromised.  This includes any systems that house customer data or services that directly interface with customer systems.<\/p>\n<p>Furthermore, the company reported that it does not utilize the \u201ccase function\u201d within Salesforce, meaning no customer support case information was accessible to the attackers. <\/p>\n<p>Dynatrace assured stakeholders that the incident caused no disruption to its business operations. The<a href=\"https:\/\/cybersecuritynews.com\/tag\/data-exposed\/\" target=\"_blank\" rel=\"noreferrer noopener\"> data exposed <\/a>in the breach is limited to business contact information. This includes the first and last names of customer contacts and their associated company identifiers.<\/p>\n<p>No sensitive credentials, financial details, or other confidential information were accessed. After a period of investigation and remediation, Salesloft notified Dynatrace on September 7th that the secure connections had been re-enabled.<\/p>\n<p>In light of the exposure of business contact information, Dynatrace has issued guidance to its customers, urging them to exercise increased caution against potential social engineering and phishing campaigns. <\/p>\n<p>The company emphasized that its employees will never contact customers via phone or email to request passwords, multi-factor authentication (MFA) codes, or other sensitive credentials. <\/p>\n<p>Customers are advised to be vigilant and verify that all communications and links originate from trusted Dynatrace domains. <\/p>\n<p>Confirmed victims of this supply chain attack include:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/palo-alto-networks-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Palo Alto Networks<\/a><\/strong>: The cybersecurity firm confirmed the exposure of business contact information and internal sales data from its CRM platform.<\/li>\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/zscaler-confirms-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Zscaler<\/a><\/strong>: The cloud security company reported that customer information, including names, contact details, and some support case content, was accessed.<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/zscaler-data-breach-exposes-customer-info-after-salesloft-drift-compromise\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\n<\/li>\n<li>\n<strong><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/data-theft-salesforce-instances-via-salesloft-drift?e=48754805\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a><\/strong>: In addition to being an investigator, Google confirmed a \u201cvery small number\u201d of its Workspace accounts were accessed through the compromised tokens.<\/li>\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/cloudflare-confirms-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cloudflare<\/a><\/strong>: Cloudflare has confirmed a data breach where a sophisticated threat actor accessed and stole customer data from the company\u2019s Salesforce instance.<\/li>\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/pagerduty-confirms-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">PagerDuty<\/a><\/strong>\u00a0has confirmed a security incident that resulted in unauthorized access to some of its data stored in Salesforce.<\/li>\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/tenable-confirms-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Tenable<\/a><\/strong>\u00a0has confirmed a data breach that exposed the contact details and support case information of some of its customers.<\/li>\n<li>\n<a href=\"https:\/\/cybersecuritynews.com\/qualys-confirms-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Qualys<\/strong><\/a> has confirmed it was impacted by a widespread supply chain attack that targeted the Salesloft Drift marketing platform, resulting in unauthorized access to a portion of its Salesforce data.<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/dynatrace-data-breach\/\">Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/dynatrace-data-breach\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Dynatrace Confirms Data Breach: Hackers Accessed Customer Data From Salesforce Dynatrace has confirmed it was impacted by a third-party data breach originating from the Salesloft Drift application, resulting in unauthorized access to customer business contact information stored in its Salesforce CRM. The company confirmed that the incident was limited to its CRM platform and did [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-6766","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6766"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6766"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6766\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6766"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6766"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6766"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}