Zscaler says it suffered data breach following Salesloft Drift compromise


We can now add Zscaler to the growing list of Salesloft customers who suffered a third-party cyberattack and lost sensitive customer information after it confirmed data was taken.

In the announcement, Zscaler explained it was a customer of Salesloft, whose AI chat platform, Salesloft Drift, was compromised. Since this platform connects with Salesforce, the miscreants managed to move laterally, stealing OAuth and refresh tokens, and accessing data from customers such as Zscaler.

Read more…
Source: TechRadar News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • NASA discloses data breach

    December 19, 2018

    The US National Aeronautics and Space Administration (NASA) admitted today to getting hacked earlier this year. In an internal memo sent to all employees, the agency said that an unknown intruder gained access to one of its servers storing the personal data of current and former employees. Social Security numbers were also compromised, NASA said. The agency ...

  • Cyber security breaches rising across UK defence sector

    December 18, 2018

    UK defence secrets are increasingly being exposed to hostile nation states after the number of security breaches in the sector rose this year. Heavily-redacted records obtained by Sky News show an increase in incidents reported to the Ministry of Defence (MoD) between January and October compared to the same period in 2017. Sky News previously revealed the ...

  • Facebook Flaw Exposes Private Photos for 6.8M Users

    December 14, 2018

    The bug allowed 1,500 apps built by 876 developers to view users’ unposted “draft” photos. Facebook on Friday disclosed a bug in its platform that it said enabled third-party apps to access unpublished photos of 6.8 million users. Facebook stores copies of photo drafts, so if someone uploads the photo but doesn’t finish posting it, the photo ...

  • Personal Information of 52.5 Million Exposed by New Google+ People API Bug

    December 10, 2018

    “With the discovery of this new bug, we have decided to expedite the shut-down of all Google+ APIs; this will occur within the next 90 days,” said David Thacker, G Suite Product Management VP. “In addition, we have also decided to accelerate the sunsetting of consumer Google+ from August 2019 to April 2019.” Google discovered the bug in ...

  • Senators Push for Data Breach and Privacy Legislation Following Marriot Breach

    December 3, 2018

    U.S. Democrat Senators Mark Warne, Ed Markey, and Richard Blumenthal published statements asking for the passage of data security and consumer privacy legislation by the Congress following the Marriot International hotel chain breach. The Marriott hotel chain disclosed a huge data breach on November 30 which affected 500 million customers who had their data stored in ...

  • 500 Million Marriott Guest Records Stolen in Starwood Data Breach

    November 30, 2018

    The world’s biggest hotel chain Marriott International today disclosed that unknown hackers compromised guest reservation database its subsidiary Starwood hotels and walked away with personal details of about 500 million guests. Starwood Hotels and Resorts Worldwide was acquired by Marriott International for $13 billion in 2016. The brand includes St. Regis, Sheraton Hotels & Resorts, W ...