Cloudflare recently disclosed a significant security incident that exposed customer support data through a supply chain attack targeting Salesloft Drift.

The breach, which occurred in August 2025, highlights growing risks from third-party integrations in today’s connected business environment.
What Happened in the Cloudflare Data Breach
Attackers gained unauthorized access to Cloudflare’s Salesforce environment by exploiting stolen OAuth tokens from the Salesloft Drift chatbot integration.
The threat group, designated as GRUB1 by Cloudflare’s security team, spent nearly a week conducting reconnaissance before stealing data using Salesforce’s Bulk API.
The incident affected hundreds of organizations worldwide that used Salesforce through Salesloft Drift connections.
Major companies including Palo Alto Networks, Zscaler, PagerDuty, and Google have confirmed similar breaches from this coordinated campaign.

Cloudflare Customer Data Exposed
The compromised information included Salesforce case objects containing:
- Customer contact details and company information
- Support ticket subject lines and correspondence
- Troubleshooting logs and configuration details
- API tokens and credentials shared during support interactions
Cloudflare identified 104 valid API tokens within the stolen data. While no suspicious activity was detected with these tokens, all were immediately rotated as a precautionary measure. The company directly notified affected customers about potential exposure.
Hide Your Digital Fingerprint
TROYPOINT Tip: Protect your identity and personal info from a data breach by using Aura which is TROYPOINT’s recommended identity theft protection.
Aura Identity Theft Protection Review
Attack Timeline and Response
The breach timeline reveals a methodical approach by attackers:
- August 9, 2025: Initial reconnaissance attempts using secret scanning tools
- August 12-14: Attackers gained access and mapped Cloudflare’s Salesforce environment
- August 16-17: Final preparation and data exfiltration using bulk download methods
Cloudflare responded quickly after being notified on August 23, implementing immediate containment measures and launching a comprehensive investigation.
The company disabled the compromised integration, purged all Salesloft software, and rotated credentials across multiple third-party services.

This incident represents part of a larger supply chain attack affecting hundreds of organizations.
Security experts praise Cloudflare’s transparent disclosure and accountability in handling the breach. The attack demonstrates how single integration points can create widespread vulnerabilities across multiple companies.
Protection Recommendations
Cloudflare recommends organizations take immediate action:
- Disconnect all Salesloft applications from Salesforce environments
- Rotate credentials for third-party integrations and any tokens shared in support cases
- Review support case histories for sensitive information exposure
- Implement regular credential rotation schedules
- Audit third-party applications for least-privilege access
- Monitor for unusual data export activities
Final Thoughts
The Cloudflare data breach serves as a stark reminder of supply chain risks in modern business environments.
While Cloudflare’s core infrastructure remained secure, the incident exposed sensitive customer information through a trusted third-party integration.
Exclusive Surfshark Discount
Your online activity is currently monitored by your ISP, app/addon/IPTV developers, government agencies, and the websites you visit.
- Become 100% anonymous while streaming and downloading.
- Use on Unlimited Devices & share 1 account with the entire family.
- Save 85% with the 24-Month Plan + Get 3 FREE Months.
Organizations must carefully evaluate and monitor all external connections to protect against similar attacks targeting business-to-business integrations.
For more details on this story, refer to the official blog post from Cloudflare and the report from Hackread.
We want to know your thoughts. What do you think about this story? Let us know in the comment section below!
Be sure to stay up-to-date with the latest streaming news, reviews, tips, and more by following the TROYPOINT Advisor with updates weekly.
This page includes affiliate links where TROYPOINT may receive a commission at no extra cost to you. Many times, visitors will receive a discount due to the special arrangements made for our fans. Learn more on my Affiliate Disclaimer page.





