Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Tenable Confirms Data Breach – Hackers Accessed Customers Contact Details

Posted on September 8, 2025September 8, 2025 By CWS

Tenable has confirmed a knowledge breach that uncovered the contact particulars and help case data of a few of its clients.

The corporate acknowledged the incident is a part of a broader information theft marketing campaign focusing on an integration between Salesforce and the Salesloft Drift advertising and marketing software, which has affected quite a few organizations.

In a public assertion, Tenable expressed its dedication to transparency and detailed the extent of the breach. The corporate’s investigation discovered that an unauthorized person had gained entry to a phase of buyer data saved inside its Salesforce occasion.

Whereas Tenable’s core merchandise and the info inside them stay safe, the incident has raised considerations concerning the safety of third-party software integrations inside main enterprise platforms.

Uncovered Knowledge

The knowledge accessed by the unauthorized celebration was restricted to information inside Tenable’s Salesforce surroundings. This included:

Generally out there enterprise contact data, akin to buyer names, enterprise electronic mail addresses, and cellphone numbers.

Regional and placement references related to buyer accounts.

Topic strains and preliminary descriptions that clients supplied when opening a help case.

Tenable has famous that presently, there isn’t any proof to counsel that the attackers have actively misused any of this data.

The breach at Tenable was not an remoted assault however is linked to a wider, refined marketing campaign that safety consultants have been monitoring. This marketing campaign particularly exploits a vulnerability within the integration between Salesforce and Salesloft Drift, a preferred gross sales engagement platform.

Attackers have been utilizing this vector to exfiltrate information from the Salesforce situations of varied firms that use the built-in functions. Tenable confirmed it was one among many organizations impacted by this coordinated effort.

Tenable’s Response and Mitigation

Upon discovering the incident, Tenable took speedy motion to safe its programs and defend buyer information. The corporate has outlined a number of steps it has taken to deal with the problem:

All doubtlessly compromised credentials for Salesforce, Drift, and associated integrations had been promptly revoked and rotated.

The Salesloft Drift software, together with all functions that built-in with it, was disabled and faraway from Tenable’s Salesforce occasion.

The corporate has additional hardened its Salesforce surroundings and different related programs to forestall future exploitation.

Tenable utilized identified Indicators of Compromise (IoCs) shared by Salesforce and cybersecurity consultants to establish and block malicious exercise.

Steady monitoring of its Salesforce and different SaaS options is ongoing to detect any exposures or uncommon exercise.

Tenable is advising its clients to stay vigilant and has really helpful that they comply with the proactive steps outlined by Salesforce and main safety consultants to safe their very own programs.

Confirmed victims of this provide chain assault embrace:

Palo Alto Networks: The cybersecurity agency confirmed the publicity of enterprise contact data and inner gross sales information from its CRM platform.

Zscaler: The cloud safety firm reported that buyer data, together with names, contact particulars, and a few help case content material, was accessed.

Google: Along with being an investigator, Google confirmed a “very small quantity” of its Workspace accounts had been accessed by the compromised tokens.

Cloudflare: Cloudflare has confirmed a knowledge breach the place a classy menace actor accessed and stole buyer information from the corporate’s Salesforce occasion.

PagerDuty has confirmed a safety incident that resulted in unauthorized entry to a few of its information saved in Salesforce.

Discover this Story Attention-grabbing! Comply with us on Google Information, LinkedIn, and X to Get Extra Instantaneous Updates.

Cyber Security News Tags:Accessed, Breach, Confirms, Contact, Customers, Data, Details, Hackers, Tenable

Post navigation

Previous Post: How to Use End-to-End Encrypted Email
Next Post: Lazarus APT Hackers Using ClickFix Technique to Steal Sensitive Intelligence Data

Related Posts

Exploiting ECS Protocol on EC2 to Exfiltrate Cross-Task IAM and Execution Role Credentials Cyber Security News
Cybersecurity Newsletter Weekly – Discord, Red Hat Data Breach, 7-Zip Vulnerabilities and Sonicwall Firewall Hack Cyber Security News
Lenovo AI Chatbot Vulnerability Let Attackers Run Remote Scripts on Corporate Machines Cyber Security News
11 Best SysAdmin Tools – 2025 Cyber Security News
Chinese APT Group IT Service Provider Leveraging Microsoft Console Debugger to Exfiltrate Data Cyber Security News
Google Warns of Cybercriminals Increasingly Attacking US Users to Steal Login Credentials Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • TransparentTribe Attack Linux-Based Systems of Indian Military Organizations to Deliver DeskRAT
  • Jingle Thief Attackers Exploiting Festive Season with Weaponized Gift Card Attacks
  • Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation
  • Warlock Ransomware Actors Exploiting Sharepoint ToolShell Zero-Day Vulnerability in New Attack Wave
  • New Python RAT Mimic as Legitimate Minecraft App Steals Sensitive Data from Users Computer

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • TransparentTribe Attack Linux-Based Systems of Indian Military Organizations to Deliver DeskRAT
  • Jingle Thief Attackers Exploiting Festive Season with Weaponized Gift Card Attacks
  • Smishing Triad Linked to 194,000 Malicious Domains in Global Phishing Operation
  • Warlock Ransomware Actors Exploiting Sharepoint ToolShell Zero-Day Vulnerability in New Attack Wave
  • New Python RAT Mimic as Legitimate Minecraft App Steals Sensitive Data from Users Computer

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News