PagerDuty Confirms Breach as Hackers Access Salesforce Accounts

PagerDuty has proactively disabled Salesloft Drift’s OAuth integration with our Salesforce instance after a third-party vulnerability allowed unauthorized access.

No core PagerDuty credentials were compromised, but customers should remain vigilant against phishing attempts.

Incident Timeline and Technical Details

PagerDuty was alerted by Salesloft to a security flaw within the Drift application’s OAuth integration flow with Salesforce.

The situation escalated when Salesloft confirmed that attackers had exploited this flaw—specifically within the OAuth 2.0 authorization code grant process—enabling a threat actor to hijack the token exchange and access PagerDuty’s Salesforce data.

Crucially, PagerDuty’s native credentials, user passwords, and API keys remained secure.

DateEventTechnical Impact
Aug 20, 2025PagerDuty notified of Drift security issueIdentification of potential OAuth flow vulnerability
Aug 23, 2025Salesloft confirms exploitation of OAuth authorization code grantPossible unauthorized access via compromised access tokens
Aug 27, 2025Salesloft issues mitigation steps for customers managing own Drift–third-party connectionsRecommendation to rotate OAuth client secrets and refresh tokens
Aug 29, 2025PagerDuty disables Drift’s OAuth integration with Salesforce; investigation continuesRevoked Drift API scopes; ensured principle of least privilege


Following Salesloft’s advisory, PagerDuty immediately:

  • Revoked all active OAuth access tokens and client credentials associated with the Drift–Salesforce integration.
  • Conducted an audit of our Salesforce audit logs to confirm no unauthorized queries or data exports occurred beyond basic account metadata.
  • Engaged our security operations center (SOC) to monitor for anomalous API calls and potential lateral movement indicators.
  • Coordinated with Google Threat Intelligence Group, Salesforce, and Salesloft to correlate Indicators of Compromise (IoCs) and YARA signatures across our environment.

Although no passwords or PagerDuty platform credentials were exposed, the OAuth breach may have revealed customer-facing data stored within Salesforce.

The potential data elements include

Data TypeDescriptionRecommended Mitigation
NamesCustomer and contact person namesVerify legitimate requests via trusted channels
Phone NumbersBusiness-line and mobile numbersIgnore unexpected inbound calls
Email AddressesNotification and support email addressesScrutinize email sender domains and URLs


Given the risk of social engineering, PagerDuty urges all users to exercise heightened caution

  • Phishing Awareness: Attackers may use known names or contact information to craft convincing email lures. Always verify email senders via official PagerDuty support channels.
  • Social Engineering: PagerDuty will never call to request passwords, 2FA codes, or secret tokens. Treat unsolicited requests with skepticism.
  • Security Hygiene: Rotate any stored OAuth credentials and enforce multi-factor authentication (MFA) on all critical Salesforce administrator accounts.

PagerDuty remains committed to transparency and rigorous security practices.

We will continue to investigate this incident, update customers on any significant findings, and collaborate with industry partners to strengthen the security posture of integrated applications like Salesloft Drift.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories