{"id":6769,"date":"2025-09-09T10:03:59","date_gmt":"2025-09-09T10:03:59","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/09\/elastic-salesloft-drift-security-incident-hackers-accessed-email-account-contains-valid-credentials\/"},"modified":"2025-09-09T10:03:59","modified_gmt":"2025-09-09T10:03:59","slug":"elastic-salesloft-drift-security-incident-hackers-accessed-email-account-contains-valid-credentials","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/09\/elastic-salesloft-drift-security-incident-hackers-accessed-email-account-contains-valid-credentials\/","title":{"rendered":"Elastic Salesloft Drift Security Incident \u2013 Hackers Accessed Email Account Contains Valid Credentials"},"content":{"rendered":"<p>    Elastic Salesloft Drift Security Incident \u2013 Hackers Accessed Email Account Contains Valid Credentials<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Elastic has disclosed a security incident stemming from a third-party breach at Salesloft Drift, which resulted in unauthorized access to an internal email account containing valid credentials. <\/p>\n<p>While the company\u2019s core Salesforce environment was not impacted, the incident exposed sensitive information contained within a limited number of emails.<\/p>\n<p>The chain of events began on August 26, 2025, when Salesloft Drift publicly disclosed a security incident affecting its platform. <\/p>\n<p>A subsequent in-depth report from Google\u2019s Threat Intelligence Group detailed the threat actor\u2019s activities related to the breach. <\/p>\n<p>As a customer using Drift for certain business applications, Elastic initiated its incident response protocols to investigate any potential impact proactively.<\/p>\n<p>Although Elastic was not directly notified of being affected, its <a href=\"https:\/\/cybersecuritynews.com\/cisos-collaborate\/\" target=\"_blank\" rel=\"noreferrer noopener\">security team<\/a> launched an immediate investigation to determine if any company or customer data was exposed.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-scope-of-the-impact\"><strong>Scope Of The Impact<\/strong><\/h2>\n<p>Elastic\u2019s investigation confirmed that its Salesforce environment was not compromised. However, the team discovered that a single email account had been exposed through the \u201cDrift Email\u201d integration. <\/p>\n<p>This exposure may have granted an unauthorized actor read-only access to emails received in that specific inbox. <\/p>\n<p>After conducting a scan of the inbox\u2019s contents, security personnel identified a small number of inbound emails that included potentially valid credentials. <\/p>\n<p>In response to this discovery, Elastic notified the customers who were potentially affected through existing support channels. <\/p>\n<p>The company has stated that any customer who did not receive a direct notification was not identified as being impacted by this credential leak.<\/p>\n<p>Immediately after learning of the Drift incident, Elastic\u2019s Information Security team took decisive action to contain the threat and assess the damage. <\/p>\n<p>The team launched a comprehensive investigation, reviewing access logs, network activity, and system configurations to determine the extent of the data exposure. <\/p>\n<p>A critical first step was to disable all Drift integrations within Elastic\u2019s environment, thereby eliminating any further risk from the compromised third-party platform. <\/p>\n<p>Concurrently, the team monitored open-source intelligence for Indicators of Compromise (IOCs) and coordinated with Drift\u2019s security team to gather additional information. <\/p>\n<p>Elastic has affirmed its commitment to transparency and protecting customer data, and its team continues to monitor for new information related to the event.<\/p>\n<p>Confirmed victims of this supply chain attack include:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/palo-alto-networks-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Palo Alto Networks<\/a><\/strong>: The cybersecurity firm confirmed the exposure of business contact information and internal sales data from its CRM platform.<\/li>\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/zscaler-confirms-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Zscaler<\/a><\/strong>: The cloud security company reported that customer information, including names, contact details, and some support case content, was accessed.<a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/zscaler-data-breach-exposes-customer-info-after-salesloft-drift-compromise\/\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a>\n<\/li>\n<li>\n<strong><a href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/data-theft-salesforce-instances-via-salesloft-drift?e=48754805\" target=\"_blank\" rel=\"noreferrer noopener\">Google<\/a><\/strong>: In addition to being an investigator, Google confirmed a \u201cvery small number\u201d of its Workspace accounts were accessed through the compromised tokens.<\/li>\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/cloudflare-confirms-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Cloudflare<\/a><\/strong>: Cloudflare has confirmed a data breach where a sophisticated threat actor accessed and stole customer data from the company\u2019s Salesforce instance.<\/li>\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/pagerduty-confirms-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">PagerDuty<\/a><\/strong>\u00a0has confirmed a security incident that resulted in unauthorized access to some of its data stored in Salesforce.<\/li>\n<li>\n<strong><a href=\"https:\/\/cybersecuritynews.com\/tenable-confirms-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Tenable<\/a><\/strong>\u00a0has confirmed a data breach that exposed the contact details and support case information of some of its customers.<\/li>\n<li>\n<a href=\"https:\/\/cybersecuritynews.com\/qualys-confirms-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Qualys<\/strong><\/a>\u00a0has confirmed it was impacted by a widespread supply chain attack that targeted the Salesloft Drift marketing platform, resulting in unauthorized access to a portion of its Salesforce data.<\/li>\n<li>\n<a href=\"https:\/\/cybersecuritynews.com\/dynatrace-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\"><strong>Dynatrace<\/strong><\/a> has confirmed it was impacted by a third-party data breach originating from the\u00a0Salesloft Drift\u00a0application, resulting in unauthorized access to customer business contact information stored in its Salesforce CRM.<\/li>\n<\/ul>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/elastic-salesloft-drift-security-incident\/\">Elastic Salesloft Drift Security Incident \u2013 Hackers Accessed Email Account Contains Valid Credentials<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/elastic-salesloft-drift-security-incident\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Elastic Salesloft Drift Security Incident \u2013 Hackers Accessed Email Account Contains Valid Credentials Elastic has disclosed a security incident stemming from a third-party breach at Salesloft Drift, which resulted in unauthorized access to an internal email account containing valid credentials. While the company\u2019s core Salesforce environment was not impacted, the incident exposed sensitive information contained [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,1812],"tags":[130],"class_list":["post-6769","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-email","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6769"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6769"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6769\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6769"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6769"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6769"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}