HackerOne has confirmed that it was among the companies affected by a recent data breach that provided unauthorized access to its Salesforce. The access was gained through a compromise of the third-party app Drift, which is owned by Salesloft.
See also: Workday confirms data breach

The bug bounty platform announced the security incident, aligning with its corporate value of “Disclosure First.” According to the company, its security team was first notified of a potential breach by Salesforce on Friday, August 22, 2025. This was subsequently confirmed by Salesloft the next day, prompting the immediate activation of HackerOne’s incident response protocols.
The company is working with Salesforce and Salesloft to investigate the full scope and impact of the breach. This incident is part of a broader attack campaign that has affected hundreds of companies.
As reported by Mandiant , malicious actors targeted Salesforce customer records by exploiting a vulnerability in the Drift marketing and sales application. By breaching Drift, attackers were able to gain unauthorized access to connected Salesforce environments, allowing the theft of sensitive customer and sales data.
See also: Lovesac: Data breach after ransomware attack

HackerOne’s confirmation adds it to a growing list of companies affected by this supply chain attack. While the investigation is ongoing, HackerOne said that a subset of its Salesforce files were compromised by unauthorized parties. However, the company expressed confidence that no vulnerable customer data was affected or exposed during the incident. This is attributed to the company’s strict internal policies and controls governing data segregation, effectively isolating sensitive vulnerability information from compromised sales and marketing data in the Salesforce environment.
HackerOne is continuing to conduct forensic analysis on the specific files that were breached to determine the exact nature of the information exposed. The company is committed to immediately contacting any customers identified as having been impacted by the breach.
See also: Plex: Recommends changing password due to data breach

This incident highlights the significant risks associated with third-party application integrations and the potential for supply chain attacks to bypass an organization's immediate security defenses.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
