The impact of the Salesloft Drift breach on Cloudflare and our customers

20 ezekg 6 9/2/2025, 5:33:41 PM blog.cloudflare.com ↗

Comments (6)

pjsg · 53m ago
I got this notification (email subject "[ACTION REQUIRED] Third-Party Compromise Impacting Cloudflare Salesforce Cases"), but, as I'm a free user, I don't even have a 'Technical Support' option under the 'Support' menu dropdown.

Have other free users also received this email?

reassess_blind · 42m ago
Click the Support Dropdown > Support > Technical Support > My Activities
bstsb · 39m ago
if you've ever submitted a support case to Cloudflare then you got the email.

check https://dash.cloudflare.com/?to=/:account/my-activities

reassess_blind · 40m ago
Is anyone aware of the other services using Salesloft Drift that were breached? Cloudflare is the first I've had reach out, but surely there were others.
bstsb · 39m ago
so far Google, Zscaler and Palo Alto Networks. looks like more to come though
htrp · 2h ago
> As part of our response to this incident, we did our own search through the compromised data to look for tokens or passwords and found 104 Cloudflare API tokens. We have identified no suspicious activity associated with those tokens, but all of these have been rotated in an abundance of caution. All customers whose data was compromised in this breach have been informed directly by Cloudflare.

Great response

> We are responsible for the choice of tools we use in support of our business. This breach has let our customers down. For that, we sincerely apologize. The rest of this blog gives a detailed timeline and detailed information on how we investigated this breach.

And a mea culpa for their 3rd party vendor choices (impressive)