Supply chain
⛓ Supply Chain
Zscaler Third-Party Breach (August 2025)
Primary Source ↗Incident Details
Salesloft Drift Supply Chain Incident: Key Details and Zscaler’s. Zscaler swiftly mitigates a security incident impacting Salesloft Drift, and ensuring robust protection against potential vulnerabilities. At Zscaler, protecting your data and maintaining transparency are core to our mission to secure, simplify and accelerate businesses transformation. We are committed to keeping you informed about key developments that may impact your organization. Zscaler was made aware of a campaign targeted at Salesloft Drift (marketing software-as-a-service) and impacting a large number of Salesloft customers. This incident involved the theft of OAuth tokens connected to Salesloft Drift, a third-party application used for automating sales workflows that integrates with Salesforce to manage leads and contact information. Third-party company: Drift (Salesloft).
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Drift (Salesloft)
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2025-08-01 Breach occurred
- 2025-08-30 Publicly disclosed