PagerDuty , a leader in digital operations management, has confirmed a security incident that resulted in unauthorized access to some of its data stored in Salesforce.
See also: Salesforce Data Theft via Compromised AI Tool

The company said that no PagerDuty platform credentials were compromised and that the breach stemmed from a vulnerability in a third-party application, Salesloft Drift.
The timeline of the incident began on August 20, 2025, when PagerDuty was first notified by Salesloft about a potential security issue related to the Drift application. Three days later, on August 23, Salesloft confirmed that attackers had exploited a vulnerability in Drift’s integration with Salesforce’s OAuth. This “abusive authorization process” allowed a threat actor to gain unauthorized access to PagerDuty’s Salesforce installation.
PagerDuty has stressed that the breach was limited in scope. In a statement, the company confirmed: “We have seen no indication that the PagerDuty platform or any other internal systems or resources beyond Salesforce were accessed.”
The company immediately disabled Salesloft Drift's access to Salesforce data upon learning of the breach and is conducting an ongoing investigation.
The potentially exposed data includes customer contact information, such as names, phone numbers, and email addresses. While PagerDuty's core services and credentials remain secure, exposing this contact information increases the risk of targeted phishing and social engineering attacks against its customers.
See also: ShinyHunters behind Salesforce data theft at Qantas, Allianz Life, LVMH

Due to this potential exposure, PagerDuty is advising all customers to exercise extreme caution. “PagerDuty will never contact anyone over the phone to request a password or any other secure information,” the company warned. “All official communication from PagerDuty is done through our trusted support channels.”
This security incident is part of a larger issue affecting Salesloft Drift customers . Background information and technical details about the vulnerability have been published by Salesloft in its trust center, as well as by Salesforce and Google's Threat Intelligence Team, which is monitoring the activity.
The incident highlights the complex security challenges companies face when integrating third-party applications into their core systems.
On August 27, Salesloft issued further recommendations for Drift customers who manage their own connections to third-party applications, signaling ongoing efforts to limit the impact of the vulnerability across the industry.
PagerDuty has assured its customers that it is taking this matter with the utmost seriousness and is working diligently to understand the full scope of the incident. The company continues to closely monitor the situation and is committed to providing updates as its investigation progresses. Customers are urged to be vigilant for unsolicited communications and report any suspicious activity.
See also: Salesforce Tableau flaws allow code execution
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Confirmed victims of this supply chain attack include:
– Palo Alto Networks: The cybersecurity company confirmed the exposure of business contact information and internal sales data from its CRM platform. – Zscaler: The cloud security company reported that customer information, including names, contact information and some support case content, was accessed. – Google: In addition to being an investigator, Google confirmed that a “very small number” of its Workspace accounts were accessed via the compromised tokens. – Cloudflare: Cloudflare confirmed a data breach in which an advanced threat actor compromised and stole customer data from the company’s Salesforce installation.
