Zscaler Blog
Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang
Salesloft Drift Supply Chain Incident: Key Details and Zscaler’s Response
At Zscaler, protecting your data and maintaining transparency are core to our mission to secure, simplify and accelerate businesses transformation. We are committed to keeping you informed about key developments that may impact your organization.
What Happened?
Zscaler was made aware of a campaign targeted at Salesloft Drift (marketing software-as-a-service) and impacting a large number of Salesloft customers. This incident involved the theft of OAuth tokens connected to Salesloft Drift, a third-party application used for automating sales workflows that integrates with Salesforce to manage leads and contact information.
The scope of the incident is confined to Salesloft’s Drift app and does not involve access to any of Zscaler's products, services or underlying systems and infrastructure.
As part of this campaign, unauthorized actors gained access to Salesloft Drift credentials of its customers including Zscaler. Following a detailed review as part of our ongoing investigation, we have determined that these credentials have allowed limited access to some Zscaler Salesforce information.
What Information May Be Affected?
The information accessed was limited to commonly available business contact details for points of contact and specific CRM related content, including:
- Names
- Business email addresses
- Job titles
- Phone numbers
- Regional/location details
- Zscaler product licensing and commercial information
- Plain text support case header content from certain cases limited to the following fields: Case Number, Opened, Preferred Contact Number, Description, Priority, Case Owner, Preferred Time Zone, Case Status, Type, Customer Case Reference, Product, Last Activity, Subject, Resolution Notes, Reason for Hand Off, Current Status / Next Plan of Action, Data Collected, Issue Summary / Business Impact, and Requestor. No attachments, files, or images were included in the incident, as it solely involved structured text data from case headers.
After extensive investigation, Zscaler has currently found no evidence to suggest misuse of this information. If anything changes, we will provide further communications and updates.
What Did Zscaler Do?
Zscaler acted swiftly to address the incident and mitigate risks. Steps taken include:
- Revoking Salesloft Drift’s access to Zscaler’s Salesforce data
- Out of an abundance of caution, rotating other API access tokens.
- Launching a detailed investigation into the scope of the event, working closely with Salesloft to assess and understand impacts as they continue investigating.
- Implementing additional safeguards and strengthening protocols to defend against similar incidents in the future.
- Immediately launched a third party risk management investigation for third party vendors used by Zscaler.
- Zscaler Customer Support team has further strengthened customer authentication protocol when responding to customer calls to safeguard against potential phishing attacks.
What You Can Do
Although the incident’s scope remains limited (as stated above) and no evidence of misuse has been found, we recommend that customers maintain heightened vigilance. Please be wary of potential phishing attacks or social engineering attempts, which could leverage exposed contact details.
Given that other organizations have suffered similar incidents stemming from Salesloft Drift, it’s crucial to exercise caution regarding unsolicited communications, including emails, phone calls, or requests for sensitive information. Always verify the source of communication and never disclose passwords or financial data via unofficial channels.
Zscaler Support will never request authentication or authorization details through unsolicited outreach, including phone calls or SMS. All official Zscaler communications come from trusted Zscaler channels. Please exercise caution and report any suspicious phishing activity to [email protected].
Need Assistance or Have Questions?
If you have concerns or need additional support, Zscaler’s Customer Success and Support teams are available via help.zscaler.com or your existing Zscaler support channels. You can also reach out to our Security team at [email protected].
Your security is our top priority. Thank you for your continued partnership with Zscaler.
Update: Blog updated on September 3rd, 2025 to include support case information impacted by the incident. Blog updated on September 7th, 2025 to include additional support case information impacted by the incident.
Frequently Asked Questions
No. The scope of the Salesloft Drift incident is entirely confined to Salesloft's Drift application. The unauthorized access did not involve any of Zscaler's products, services, underlying systems, or infrastructure. The only information accessed was limited Salesforce CRM contact data, names, business email addresses, job titles, phone numbers, regional details, and support case header fields, from Zscaler's use of Salesloft Drift as a third-party sales workflow tool.
The accessed data was limited to business contact information and CRM-related content: names, business email addresses, job titles, phone numbers, and regional/location details. Additionally, support case header fields were accessed, including case numbers, priority, status, product type, and description fields. No attachments, files, images, passwords, financial data, or Zscaler product or system credentials were included. Zscaler has found no current evidence of misuse of any accessed information.
Customers should maintain heightened vigilance for phishing emails, unsolicited phone calls, or social engineering attempts that may leverage exposed contact details. Verify the source of any unexpected communication from parties claiming to be Zscaler. Note that Zscaler Support will never request authentication or authorization details through unsolicited outreach. Report any suspicious activity to [email protected]. For direct assistance, contact Zscaler Customer Success and Support at help.zscaler.com or via your existing support channels.
This incident affected a large number of Salesloft Drift customers — it was not specific to Zscaler. The unauthorized actors targeted Salesloft Drift's platform directly, stealing OAuth tokens connected to Salesloft Drift accounts across multiple customer organizations. Zscaler was one of many organizations impacted. If your organization also uses or has used Salesloft Drift, you should contact Salesloft directly to assess whether your organization's credentials or CRM data were also affected.
Zscaler took immediate action including: revoking Salesloft Drift's access to Zscaler Salesforce data; rotating other API access tokens as a precaution; launching a detailed investigation in coordination with Salesloft; initiating a broader third-party risk management review of all third-party vendors; implementing additional safeguards and strengthened protocols; and enhancing customer authentication procedures in Zscaler Support to guard against social engineering exploitation of the accessed contact data.
War dieser Beitrag nützlich?
Haftungsausschluss: Dieser Blog-Beitrag wurde von Zscaler ausschließlich zu Informationszwecken erstellt und wird ohne jegliche Garantie für Richtigkeit, Vollständigkeit oder Zuverlässigkeit zur Verfügung gestellt. Zscaler übernimmt keine Verantwortung für etwaige Fehler oder Auslassungen oder für Handlungen, die auf der Grundlage der bereitgestellten Informationen vorgenommen werden. Alle in diesem Blog-Beitrag verlinkten Websites oder Ressourcen Dritter werden nur zu Ihrer Information zur Verfügung gestellt, und Zscaler ist nicht für deren Inhalte oder Datenschutzmaßnahmen verantwortlich. Alle Inhalte können ohne vorherige Ankündigung geändert werden. Mit dem Zugriff auf diesen Blog-Beitrag erklären Sie sich mit diesen Bedingungen einverstanden und nehmen zur Kenntnis, dass es in Ihrer Verantwortung liegt, die Informationen zu überprüfen und in einer Ihren Bedürfnissen angemessenen Weise zu nutzen.
Erhalten Sie die neuesten Zscaler Blog-Updates in Ihrem Posteingang
Mit dem Absenden des Formulars stimmen Sie unserer Datenschutzrichtlinie zu.



