Skip to main content
Back to overview
Medium

OneDigital Investment Advisors LLC Reports Data Compromise in Salesforce/Drift Breach

The impact of the Salesloft Drift breach on Cloudflare and our customers Sourov Zaman , Craig Strubhart , and Grant Bourzikas This post is also available in Deutsch , Español (Latinoamérica) , Français , 日本語 , 한국어 ,…

Key points

  • Personal data compromised on August 12, 2025.
  • Affected up to 28,414 individuals.
  • Part of a broader supply chain attack involving Salesforce and Salesloft's Drift integration.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Confidentiality impact

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality

Published
Aug 12, 2025
Updated
Jul 22, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

OnedigitalData DisclosureOneDigital Investment Advisors LLC ReportsSalesforceSalesloft DriftCloudflare andSourov ZamanCraig StrubhartGrant Bourzikas ThisDeutsch

Quick context

Questions about this signal

What happened in this signal?

The impact of the Salesloft Drift breach on Cloudflare and our customers Sourov Zaman , Craig Strubhart , and Grant Bourzikas This post is also available in Deutsch , Español (Latinoamérica) , Français , 日本語 , 한국어 , 繁體中文 , 简体中文 , Português , and العربية . On August 23rd, Cloudflare was notified that we (and our customers) are affected by the Salesloft Drift breach. Because of this breach, someone outside Cloudflare got access to our Salesforce instance, which we use for customer support and internal customer case management, and some of the data it contains. Most of this information is customer contact information and basic support case data, but some customer support interactions may reveal information about a customer's configuration and could contain sensitive information like access tokens. Given that Salesforce support case data contains the contents of support tickets with Cloudflare, any information that a customer may have shared with Cloudflare in our support system—including logs, tokens or passwords—should be considered compromised, and we strongly urge you to rotate any credentials that you may have shared with us through this channel. As part of our response to this incident, we did our own search through the compromised data to look for tokens or passwords and found 104 Cloudflare API tokens. We have identified no suspicious activity associated with those tokens, but all of these have been rotated in an abundance of caution. All customers whose data was compromised in this breach have been informed directly by Cloudflare. No Cloudflare services or infrastructure were compromised as a result of this breach. We are responsible for the choice of tools we use in support of our business. This breach has let our customers down. For that, we sincerely apologize. The rest of this blog gives a detailed timeline and detailed information on how we investigated this breach. Last week, Cloudflare became aware of suspicious activity within our Salesforce tenant and learned that we, as well as hundreds of other companies, had become the target of a threat actor that was able to successfully exfiltrate the text fields of support cases from our Salesforce instance. Our security team immediately began an investigation, cut off the threat actor’s access, and took a number of steps, detailed below, to secure our environment. We are writing this blog to detail what happened, how we responded, and to help our customers and others understand how to protect themselves from this incident. Cloudflare uses Salesforce to keep track of who our customers are and how they use our services, and we use it as a support tool to interact with our customers. An important detail to understand as part of this incident is that the threat actor only accessed data in Salesforce “cases,” which may be created when Cloudflare sales and support team members need to comment to each other internally in order to support our customers; they are also created when customers interact with Cloudflare support. Salesforce had an integration with the Salesloft Drift chatbot, which Cloudflare used to give anyone who visited our website a way to contact us. As Salesloft has announced , a threat actor breached their systems. As part of the breach, the threat actor was able to obtain OAuth credentials associated with the Salesloft Drift chat agent’s Salesforce integration to exfiltrate data from Salesloft customers’ Salesforce instances. Our investigation revealed that this was part of a sophisticated supply chain attack targeting business-to-business third-party integrations, affecting hundreds of organizations globally that were customers of Salesloft. Cloudforce One —Cloudflare’s threat intelligence & research team—has classified the advanced threat actor as GRUB1 . Additional disclosures from Google’s Threat Intelligence Group aligned with the activity we observed in our environment. Our investigation showed the threat actor compromised and exfiltrated data from our Salesforce tenant between August 12-17, 2025, following initial reconnaissance observed on August 9, 2025. A detailed analysis confirmed the exposure was limited to Salesforce case objects, which primarily consist of customer support tickets and their associated data within our Salesforce tenant. These case objects contain customer contact information related to the support case, case subject lines, and the body of the case correspondence—but not any attachments to the cases. Cloudflare does not request or require customers to share secrets, credentials, or API keys in support cases. However, in some troubleshooting scenarios, customers may paste keys, logs, or other sensitive information into the case text fields. Anything shared through this channel should now be considered compromised. We believe this incident was not an isolated event but that the threat actor intended to harvest credentials and customer information for future attacks. Given that hundreds of organizations were affected through this Drift compromise, we suspect the threat actor will use this information to launch targeted attacks against customers across the affected organizations. This post provides a timeline of the attack, details our response, and offers security recommendations to help other organizations mitigate similar threats. Throughout this blog post, all dates and times are in UTC. When Salesforce and Salesloft notified us on August 23, 2025, that the Drift integration had been abused across multiple organizations, including Cloudflare, we immediately launched a company-wide Security Incident Response. We activated cross-functional teams, pulling together experts from Security, IT, Product, Legal, Communications, and business leadership under a single, unified incident command structure. We set up four clear priority workstreams with the goal to protect our customers and Cloudflare: Immediate Threat Containment: We cut off all threat actor access by disabling the compromised Drift integration, conducted forensic analysis to understand the scope of the compromise, and eliminated the active threat from our environment.

When was this signal reported?

Shadow Tier lists Aug 12, 2025 as the signal date.

Which organization is connected to this signal?

Onedigital is the organization connected to this public signal.

Explore Onedigital
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence