{"id":6802,"date":"2025-09-10T10:05:37","date_gmt":"2025-09-10T10:05:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/10\/hackerone-confirms-data-breach-hackers-gained-unauthorized-access-to-salesforce-instance\/"},"modified":"2025-09-10T10:05:37","modified_gmt":"2025-09-10T10:05:37","slug":"hackerone-confirms-data-breach-hackers-gained-unauthorized-access-to-salesforce-instance","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/10\/hackerone-confirms-data-breach-hackers-gained-unauthorized-access-to-salesforce-instance\/","title":{"rendered":"HackerOne Confirms Data Breach \u2013 Hackers Gained Unauthorized Access To Salesforce Instance"},"content":{"rendered":"<p>    HackerOne Confirms Data Breach \u2013 Hackers Gained Unauthorized Access To Salesforce Instance<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>HackerOne has confirmed it was among the companies affected by a recent data breach that provided unauthorized access to its Salesforce instance. The access was gained through a compromise of the third-party application Drift, which Salesloft owns.<\/p>\n<p>The <a href=\"https:\/\/cybersecuritynews.com\/what-is-bug-bounty-program-why-organization-needs-them\/\" target=\"_blank\" rel=\"noreferrer noopener\">bug bounty<\/a> platform announced the security incident, aligning with its company value of \u201cDefault to Disclosure.\u201d According to the company, its security team was first notified of a potential compromise by Salesforce on Friday, August 22, 2025.<\/p>\n<p>This was subsequently confirmed by Salesloft the following day, prompting HackerOne to activate its incident response protocols immediately.<\/p>\n<p>The company is working in partnership with both Salesforce and <a href=\"https:\/\/cybersecuritynews.com\/salesloft-drift-cyberattack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Salesloft<\/a> to investigate the full scope and impact of the breach. This incident is part of a broader attack campaign that has impacted hundreds of companies.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-hackerone-confirms-data-breach\"><strong>HackerOne Confirms Data Breach<\/strong><\/h2>\n<p>As detailed in a report by Google\u2019s Mandiant, threat actors targeted Salesforce customer records by exploiting a vulnerability within the Drift marketing and sales application. <\/p>\n<p>By compromising Drift, attackers were able to pivot and gain unauthorized access to connected Salesforce environments, allowing for the theft of sensitive customer and sales data. <\/p>\n<p>HackerOne\u2019s <a href=\"https:\/\/www.hackerone.com\/blog\/salesforce-drift-incident-response-update\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">confirmation places<\/a> it on a growing list of firms responding to this <a href=\"https:\/\/cybersecuritynews.com\/supply-chain-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">supply chain attack<\/a>. While the investigation remains ongoing, HackerOne stated that a subset of records within its Salesforce instance was accessed by the unauthorized parties.<\/p>\n<p>However, the company expressed confidence that no customer vulnerability data was impacted or exposed during the incident. <\/p>\n<p>This is attributed to the firm\u2019s strict internal policies and controls, which govern data segmentation, effectively siloing sensitive vulnerability information away from the compromised sales and marketing data in the Salesforce environment.<\/p>\n<p>HackerOne is continuing to conduct a <a href=\"https:\/\/cybersecuritynews.com\/what-is-digital-forensics\/\" target=\"_blank\" rel=\"noreferrer noopener\">forensic analysis<\/a> on the specific records accessed to determine the exact nature of the exposed information.<\/p>\n<p>The company has committed to communicating directly with any customers who are identified as being impacted by the breach. <\/p>\n<p>This incident highlights the significant risks associated with third-party application integrations and the potential for supply chain attacks to bypass an organization\u2019s direct security defenses.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackerone-confirms-data-breach\/\">HackerOne Confirms Data Breach \u2013 Hackers Gained Unauthorized Access To Salesforce Instance<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackerone-confirms-data-breach\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>HackerOne Confirms Data Breach \u2013 Hackers Gained Unauthorized Access To Salesforce Instance HackerOne has confirmed it was among the companies affected by a recent data breach that provided unauthorized access to its Salesforce instance. The access was gained through a compromise of the third-party application Drift, which Salesloft owns. The bug bounty platform announced the [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,156],"tags":[130],"class_list":["post-6802","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6802"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6802"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6802\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6802"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6802"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6802"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}