Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Data Breaches

Tenable Confirms Data Breach in Widespread Salesloft Supply-Chain Attack

September 8, 2025
Reading Time: 2 mins read
Tenable Confirms Data Breach in Widespread Salesloft Supply-Chain Attack

Cybersecurity company Tenable has allegedly been affected by a significant supply chain attack that has impacted numerous organizations. The breach is reportedly linked to a vulnerability in the integration between Salesforce and the Salesloft Drift marketing application. Tenable, a prominent American cybersecurity company known for its vulnerability management solutions, confirmed that an unauthorized user gained access to a segment of its customer information stored within its Salesforce instance. The company has stated that its core products and the data within them remain secure.

The incident is part of a broader, sophisticated campaign that has targeted the Salesforce integrations of many companies. Tenable has assured its customers that it took immediate action to secure its systems by revoking and rotating all potentially compromised credentials, disabling and removing the vulnerable application, and hardening its Salesforce environment. The company has also said that there is currently no evidence to suggest that the accessed information has been actively misused.
The following data was allegedly compromised in the breach:
  • Customer names, business email addresses, and phone numbers.
  • Regional and location references associated with customer accounts.
  • Subject lines and initial descriptions provided by customers when opening a support case.

Other confirmed victims of this supply chain attack include:

  • Qualys 🇺🇸 – A cloud security and compliance solutions provider.
  • Zscaler 🇺🇸 – A cloud security company.
  • Google 🇺🇸 – A multinational technology company.
  • Cloudflare 🇺🇸 – A web infrastructure and website security company.
  • PagerDuty 🇺🇸 – An incident response platform.
  • Palo Alto Networks 🇺🇸 – A multinational cybersecurity company.
Tags: CyberSecuritydata-breachSalesforceSalesloft Driftsupply-chain attackTenable
ShareTweet

Related Posts

Uganda Ministry of Agriculture MAAIF Suffers Data Breach
Data Breaches

Uganda Ministry of Agriculture MAAIF Suffers Data Breach

April 27, 2026
Ellipal Cryptocurrency Wallet Suffers Alleged Data Breach
Data Breaches

Ellipal Cryptocurrency Wallet Suffers Alleged Data Breach

April 27, 2026
BlackSexFinder Adult Platform Suffers Massive Data Breach
Data Breaches

BlackSexFinder Adult Platform Suffers Massive Data Breach

April 27, 2026
Jeff Honeycutt Insurance Agency Data Breach Exposes Client Info
Data Breaches

Jeff Honeycutt Insurance Agency Data Breach Exposes Client Info

April 27, 2026
FFWPU and Tongil Group Face Extensive Data Breach
Data Breaches

FFWPU and Tongil Group Face Extensive Data Breach

April 27, 2026
Terra West Management Services Suffers Major Data Breach
Data Breaches

Terra West Management Services Suffers Major Data Breach

April 24, 2026
Next Post
Russian Engineering Firm Okan Allegedly Hit by WarLock Ransomware

Russian Engineering Firm Okan Allegedly Hit by WarLock Ransomware

Lynx Ransomware Allegedly Breaches US Architecture Firm BGKT Architects

Lynx Ransomware Allegedly Breaches US Architecture Firm BGKT Architects

Recommended Stories

Pick n Pay Data Breach Sparks Concerns Over Customer Privacy

Pick n Pay Data Breach Sparks Concerns Over Customer Privacy

December 26, 2024
High Society Group Allegedly Breaches Belgian Company Daoust, Threatening Data Security

High Society Group Allegedly Breaches Belgian Company Daoust, Threatening Data Security

May 7, 2024
Stimulation.Studio Data Breach Exposes User Information

Stimulation.Studio Data Breach Exposes User Information

April 8, 2026

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?