Supply chain ⛓ Supply Chain

BugCrowd Third-Party Breach (September 2025)

📅 2025-09-01 🏢 Drift (Salesloft)
Primary Source ↗

Incident Details

Update: Bugcrowd Response to Salesloft Drift Third-Party Security Event | @Bugcrowd. We want to share an update to our blog post regarding the recent unauthorized access to Salesloft’s Drift application, which was integrated with Bugcrowd’s Salesforce instance. Bugcrowd is among the more than 700 companies impacted by this incident. We have no reason to believe this activity affected Bugcrowd’s platform, customer vulnerability information, its broader systems, […]. As we discuss further below, any potential impact to Bugcrowd and its customers would be the result of the integration of Salesloft’s Drift application with Bugcrowd’s Salesforce instance. Third-party company: Drift (Salesloft).

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Drift (Salesloft)
Supply Chain Attack
✅ Confirmed third-party / vendor compromise

Timeline

  1. 2025-09-01 Breach occurred
  2. 2025-09-05 Publicly disclosed