Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Tenable Confirms Data Breach – Hackers Accessed Customers Contact Details

Posted on September 8, 2025September 8, 2025 By CWS

Tenable has confirmed a knowledge breach that uncovered the contact particulars and help case data of a few of its clients.

The corporate acknowledged the incident is a part of a broader information theft marketing campaign focusing on an integration between Salesforce and the Salesloft Drift advertising and marketing software, which has affected quite a few organizations.

In a public assertion, Tenable expressed its dedication to transparency and detailed the extent of the breach. The corporate’s investigation discovered that an unauthorized person had gained entry to a phase of buyer data saved inside its Salesforce occasion.

Whereas Tenable’s core merchandise and the info inside them stay safe, the incident has raised considerations concerning the safety of third-party software integrations inside main enterprise platforms.

Uncovered Knowledge

The knowledge accessed by the unauthorized celebration was restricted to information inside Tenable’s Salesforce surroundings. This included:

Generally out there enterprise contact data, akin to buyer names, enterprise electronic mail addresses, and cellphone numbers.

Regional and placement references related to buyer accounts.

Topic strains and preliminary descriptions that clients supplied when opening a help case.

Tenable has famous that presently, there isn’t any proof to counsel that the attackers have actively misused any of this data.

The breach at Tenable was not an remoted assault however is linked to a wider, refined marketing campaign that safety consultants have been monitoring. This marketing campaign particularly exploits a vulnerability within the integration between Salesforce and Salesloft Drift, a preferred gross sales engagement platform.

Attackers have been utilizing this vector to exfiltrate information from the Salesforce situations of varied firms that use the built-in functions. Tenable confirmed it was one among many organizations impacted by this coordinated effort.

Tenable’s Response and Mitigation

Upon discovering the incident, Tenable took speedy motion to safe its programs and defend buyer information. The corporate has outlined a number of steps it has taken to deal with the problem:

All doubtlessly compromised credentials for Salesforce, Drift, and associated integrations had been promptly revoked and rotated.

The Salesloft Drift software, together with all functions that built-in with it, was disabled and faraway from Tenable’s Salesforce occasion.

The corporate has additional hardened its Salesforce surroundings and different related programs to forestall future exploitation.

Tenable utilized identified Indicators of Compromise (IoCs) shared by Salesforce and cybersecurity consultants to establish and block malicious exercise.

Steady monitoring of its Salesforce and different SaaS options is ongoing to detect any exposures or uncommon exercise.

Tenable is advising its clients to stay vigilant and has really helpful that they comply with the proactive steps outlined by Salesforce and main safety consultants to safe their very own programs.

Confirmed victims of this provide chain assault embrace:

Palo Alto Networks: The cybersecurity agency confirmed the publicity of enterprise contact data and inner gross sales information from its CRM platform.

Zscaler: The cloud safety firm reported that buyer data, together with names, contact particulars, and a few help case content material, was accessed.

Google: Along with being an investigator, Google confirmed a “very small quantity” of its Workspace accounts had been accessed by the compromised tokens.

Cloudflare: Cloudflare has confirmed a knowledge breach the place a classy menace actor accessed and stole buyer information from the corporate’s Salesforce occasion.

PagerDuty has confirmed a safety incident that resulted in unauthorized entry to a few of its information saved in Salesforce.

Discover this Story Attention-grabbing! Comply with us on Google Information, LinkedIn, and X to Get Extra Instantaneous Updates.

Cyber Security News Tags:Accessed, Breach, Confirms, Contact, Customers, Data, Details, Hackers, Tenable

Post navigation

Previous Post: How to Use End-to-End Encrypted Email
Next Post: Lazarus APT Hackers Using ClickFix Technique to Steal Sensitive Intelligence Data

Related Posts

Infamous BreachForums Is Back Online With All Accounts and Posts Restored Cyber Security News
Secret Blizzard Group’s ApolloShadow Malware Install Root Certificates on Devices to Trust Malicious Sites Cyber Security News
VirtualBox 7.2 Released With Support for Windows 11/Arm VMs and Bug Fixes Cyber Security News
APT MuddyWater Attacking CFOs Leveraging OpenSSH, Enables RDP, and Scheduled Task Cyber Security News
Hackers Actively Attacking Linux SSH Servers to Deploy TinyProxy or Sing-box Proxy Tools Cyber Security News
FUJIFILM Printers Vulnerability Let Attackers Trigger DoS Condition Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • 45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage
  • How to Use Incognito Mode Effectively
  • Progress OpenEdge AdminServer Vulnerability Let Attackers Execute Remote Code
  • Windows Defender Vulnerability Allows Service Hijacking and Disablement via Symbolic Link Attack
  • GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • 45 Previously Unreported Domains Expose Longstanding Salt Typhoon Cyber Espionage
  • How to Use Incognito Mode Effectively
  • Progress OpenEdge AdminServer Vulnerability Let Attackers Execute Remote Code
  • Windows Defender Vulnerability Allows Service Hijacking and Disablement via Symbolic Link Attack
  • GitHub Account Compromise Led to Salesloft Drift Breach Affecting 22 Companies

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News