Cloudflare has confirmed a data breach, in which a threat actor gained access and stole customer data from the Salesforce .

The breach was part of a broader supply chain attack that exploited a vulnerability in the chatbot Salesloft Drift, affecting hundreds of organizations worldwide.
In a detailed disclosure, Cloudflare explained that the threat actor (which it named GRUB1), gained unauthorized access to the Salesforce environment between August 12 and 17, 2025.
The company uses Salesforce for customer support and internal case management. The hackers were able to extract data from Salesforce “cases,” which are essentially customer support requests.
See also: Cloudflare blocked the largest DDoS attack (11.5 Tbps)
Cloudflare: Data Breach
The information that was compromised was limited to the text fields of these support cases. This data includes customer contact information, case subject lines, and the “body” of the correspondence. Cloudflare emphasized that while they do not ask customers to share sensitive information in support requests, any credentials, API keys, logs, or passwords that customers may have pasted into the text fields should now be considered compromised.
No case attachments were accessed and no Cloudflare services or core infrastructure were compromised as a result of this incident.

As part of its response, Cloudflare conducted an investigation into the stolen data and discovered 104 of its own API tokens. While they were not associated with suspicious activity, these tokens have been replaced as a precautionary measure. All customers whose data was compromised have been notified by Cloudflare as of September 2, 2025.
The investigation revealed that the attack began with reconnaissance on August 9, with the initial breach occurring on August 12. The threat actor used stolen credentials from the Salesforce Drift integration to gain access and systematically explore Cloudflare’s Salesforce environment. On August 17, it proceeded to extract support case data.
See also: Pennsylvania Attorney General's Office hit by ransomware attack
Cloudflare's reaction
Cloudflare was officially notified of the vulnerability by Salesforce and Salesloft on August 23, at which time it began investigating and took additional measures to address the incident.
The company's remediation efforts included immediately disabling the compromised Drift integration, replacing credentials for all third-party services connected to Salesforce, and analyzing the stolen data to determine the impact on customers.
In a statement , Cloudflare took responsibility for the incident, saying: “We are responsible for the choice of tools we use to support our business. This breach has disappointed our customers. For that, we sincerely apologize.” The company is urging all customers to replace any credentials they may have shared through the support channel.
See also: Jaguar Land Rover suffered a cyberattack
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The incident highlights the growing risks associated with third-party integrations into the SaaS ecosystem.

Other victims of the Salesloft attack
Confirmed victims of this supply chain attack are:
Palo Alto Networks: The cybersecurity company confirmed the exposure of business contact information and internal sales data from its CRM platform.
Zscaler: The cloud security company reported that customer information, including names, contact information, and some support case content, was breached.
Google: Google confirmed that a “very small number” of Workspace accounts were affected through the compromised tokens.
The data breach at Cloudflare and others highlights one of the biggest weaknesses of the modern SaaS ecosystem: dependencies on third-party providers. Even a leading company can be exposed due to a vulnerability in an integration tool that, under normal circumstances, is considered innocent. The incident proves that security is not only a matter of shielding your own infrastructure, but also of constantly assessing all partners. For businesses, the Cloudflare case serves as a reminder that cloud supply chains can become the most vulnerable point of defense.
