Skip to main content
Salesloft Drift Data Breach: What We Know and What We're Doing
Emerging Issue

Salesloft Drift Data Breach: What We Know and What We're Doing

At Tanium, trust and transparency are among our guiding principles. We are committed to keeping you informed about important updates regarding your information.

What happened?

We want to let you know about a recent social engineering campaign targeting Salesforce customers, including attackers stealing OAuth tokens from the third-party Salesloft Drift application. Salesloft Drift is used for automating sales processes, and it integrates with Salesforce databases, pulling relevant information such as leads and contact details into the platform to help coordinate pitches. The unauthorized access of Salesloft Drift is in line with similar Salesforce-related incidents which have impacted many organizations in recent weeks.

We were recently notified that the attackers had obtained Tanium credentials from Salesloft Drift and may have been able to access Tanium’s Salesforce data. Based on our investigation, the threat actors had limited access to our Salesforce data and the impact of their unauthorized access to Salesloft Drift was limited to Salesforce and no other Tanium systems.

What information was involved?

Based on our investigation, the information that may have been compromised in our Salesforce instance was primarily limited to the following commonly available business contact information:

  • Names
  • Business Email Addresses
  • Phone numbers
  • Regional/location references

At this time, Tanium has no evidence that any of our customers’ information has been misused. However, we wanted to notify you about this incident so you can take the necessary precautions.

Additionally, we can confirm definitively that unauthorized access was limited to our Salesforce data and no access to the Tanium platform or any other internal systems or resources took place.

What are we doing?

The following steps have been taken to contain and resolve the issue:

  1. Ensured that Salesloft Drift’s access to Tanium’s Salesforce data has been disabled.
  2. Launched an extensive investigation to ensure all aspects of this event are fully understood and any additional mitigations which may be required have been identified and applied
  3. Leveraged SSPM technology to further strengthen detection and controls around platform integrations

What can you do?

Given that some of the potentially exposed information includes names, phone numbers and email addresses, Tanium recommends extra vigilance with respect to potential phishing and social engineering attacks.

For more information

If you have any questions or concerns, please do not hesitate to contact our Global Support team at help.tanium.com.

It is important to remember that Tanium will never contact anyone by phone to request a password or any other secure details. All official communication from Tanium comes through our trusted support channels.

To learn more about what Tanium does to secure our data and that of our customers, please visit our Security at Tanium page.