Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home Data Breaches

Zscaler Customer Data Allegedly Exposed via Salesloft Supply-Chain Attack

September 2, 2025
Reading Time: 2 mins read
Zscaler Customer Data Allegedly Exposed via Salesloft Supply-Chain Attack

Cybersecurity giant Zscaler has allegedly fallen victim to a significant data breach stemming from a supply-chain attack that compromised one of its third-party vendors, Salesloft. The incident has reportedly led to the exposure of sensitive customer information. Zscaler, a San Jose, California-based company, is a major player in cloud security, providing services to thousands of organizations worldwide to secure their internet traffic and internal applications.   

The breach was initiated through the compromise of Salesloft’s Drift, a popular marketing and sales engagement platform. Threat actors, identified as a group tracked as UNC6395, allegedly leveraged stolen OAuth tokens from the Drift service to gain unauthorized access to Zscaler’s Salesforce environment. This access allowed the attackers to exfiltrate a range of customer data. Zscaler has stated that the breach was limited to its Salesforce instance and did not impact its core products, services, or infrastructure.

The compromised information allegedly includes a variety of customer data. While a complete list has not been officially disclosed, the exposed data is reported to include:   

  • Names
  • Business email addresses
  • Job titles
  • Phone numbers
  • Regional/location details
  • Zscaler product licensing and commercial information
  • Content from certain support cases   
In response to the incident, Zscaler has revoked all integrations with Salesloft Drift, rotated API tokens, and enhanced its customer authentication protocols for support. The company is actively investigating the breach and has emphasized that it has not observed any misuse of the stolen information. However, customers are advised to be vigilant against potential phishing and social engineering attacks that could leverage this data.
Tags: customer-dataCyberSecuritydata-breachDriftSalesforceSalesloftsupply-chain attackUNC6395Zscaler
ShareTweet

Related Posts

Uganda Ministry of Agriculture MAAIF Suffers Data Breach
Data Breaches

Uganda Ministry of Agriculture MAAIF Suffers Data Breach

April 27, 2026
Ellipal Cryptocurrency Wallet Suffers Alleged Data Breach
Data Breaches

Ellipal Cryptocurrency Wallet Suffers Alleged Data Breach

April 27, 2026
BlackSexFinder Adult Platform Suffers Massive Data Breach
Data Breaches

BlackSexFinder Adult Platform Suffers Massive Data Breach

April 27, 2026
Jeff Honeycutt Insurance Agency Data Breach Exposes Client Info
Data Breaches

Jeff Honeycutt Insurance Agency Data Breach Exposes Client Info

April 27, 2026
FFWPU and Tongil Group Face Extensive Data Breach
Data Breaches

FFWPU and Tongil Group Face Extensive Data Breach

April 27, 2026
Terra West Management Services Suffers Major Data Breach
Data Breaches

Terra West Management Services Suffers Major Data Breach

April 24, 2026
Next Post
Major Dutch Flower Exporter D. Visser & Zonen BV Allegedly Breached – 28GB of Data for Sale

Major Dutch Flower Exporter D. Visser & Zonen BV Allegedly Breached - 28GB of Data for Sale

Atomic and Exodus Crypto Wallets at Risk from Deceptive npm Package

Atomic and Exodus Crypto Wallets at Risk from Deceptive npm Package

Recommended Stories

Alleged T-Mobile Data Breach Exposed by Threat Actor on Dark Web Forum

Alleged T-Mobile Data Breach Exposed by Threat Actor on Dark Web Forum

October 15, 2024
L’Orange Bleu Data Breach Exposes Fitness Club Financials and Manager PII

L’Orange Bleu Data Breach Exposes Fitness Club Financials and Manager PII

January 6, 2026
MedicaMall Allegedly Breached by CyberNiggers, Customer Data Exposed

MedicaMall Allegedly Breached by CyberNiggers, Customer Data Exposed

August 29, 2024

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?