HomeSecurityDynatrace confirms data breach

Dynatrace confirms data breach

Dynatrace has confirmed that it was affected by a third-party data breach originating from the Salesloft Drift app , resulting in unauthorized access to customer contact business information stored in the company's Salesforce CRM

See also: Qualys confirms data breach via Salesloft Drift

Dynatrace

The company confirmed that the incident was limited to its CRM platform and did not impact any of Dynatrace's core products, services, or sensitive customer environments.

The security incident began in August 2025, when malicious actors compromised Salesloft’s Drift app, a popular third-party tool used for customer engagement. This breach allowed attackers to gain unauthorized access to the Salesforce environments of companies using the app.

In response to the attack, Salesloft and Salesforce proceeded to disable the compromised connections and began notifying affected customers, including Dynatrace.

Upon being notified of the third-party breach, Dynatrace’s security team took immediate action by disabling the Drift application in its environment to break the connection and prevent further unauthorized access. The company launched a comprehensive investigation, bringing in external cybersecurity experts to determine the full scope of the incident.

See also: Salesloft Drift attack linked to GitHub breach

Dynatrace confirms data breach

The investigation confirmed that the malicious activity was limited to the Salesforce CRM instance, which the company uses for customer relationship management and marketing activities. Dynatrace clarified that none of its own products or services were compromised. This includes any systems that host customer data or services that directly interact with customer systems.

Additionally, the company said it does not use the “case feature” in Salesforce, meaning that no customer support case information was accessible to the attackers. The company assured stakeholders that the incident did not cause any disruption to its business operations. The data exposed in the breach is limited to business contact information, including customer contact names and associated company identifiers. No sensitive credentials, financial details, or other confidential information.

See also: Wealthsimple: Supply chain attack led to data breach

Dynatrace confirms data breach

After a period of investigation and remediation, Salesloft notified Dynatrace on September 7 that secure connections had been re-enabled. In light of the exposure of business contact information, the company issued guidance to its customers, urging them to be more vigilant against potential social engineering and phishing campaigns . The company emphasized that its employees will never contact customers by phone or email to request passwords, multi-factor authentication (MFA) codes, or other sensitive credentials. Customers are advised to be vigilant and verify that all communications and links are coming from trusted Dynatrace domains.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS