Cloudflare Victimized in SalesLoft Data Breach

Cloudflare, a leading internet security and performance company, recently fell victim to a data breach through SalesLoft, a sales engagement platform. The breach exposed sensitive information, highlighting the risks associated with third-party service providers. This incident underscores the importance of robust cybersecurity measures and vigilant monitoring of vendor relationships to prevent unauthorized access and data leaks. The attack on Cloudflare via SalesLoft demonstrates how threat actors exploit trusted business tools to infiltrate larger organizations. Cybercriminals targeted SalesLoft's systems, gaining access to customer data, including that of Cloudflare. This breach serves as a cautionary tale for enterprises relying heavily on third-party platforms, emphasizing the need for comprehensive security assessments and continuous oversight. In response to the breach, Cloudflare has taken immediate steps to mitigate the impact, including enhancing security protocols and cooperating with SalesLoft to investigate the incident thoroughly. The company reassures its customers that it is committed to transparency and protecting user data. This event also prompts a broader discussion on the cybersecurity challenges posed by interconnected digital ecosystems and the necessity for collaborative defense strategies. Organizations must prioritize cybersecurity hygiene, including multi-factor authentication, regular audits, and incident response planning, to safeguard against similar threats. The Cloudflare-SalesLoft breach highlights the evolving tactics of cyber adversaries and the critical need for proactive defense mechanisms in today's digital landscape.

This Cyber News was published on www.infosecurity-magazine.com. Publication date: Wed, 03 Sep 2025 11:10:03 +0000


Cyber News related to Cloudflare Victimized in SalesLoft Data Breach

Cloudflare discloses breach related to stolen Okta data - Last fall, Cloudflare announced it mitigated an attempted cyberattack stemming from the infamous Okta breach. Cloudflare disclosed in a blog post that it had been breached by an unnamed nation-state threat actor using an access token and three ...
1 year ago Techtarget.com
Cloudflare Victimized in SalesLoft Data Breach - Cloudflare, a leading internet security and performance company, recently fell victim to a data breach through SalesLoft, a sales engagement platform. The breach exposed sensitive information, highlighting the risks associated with third-party ...
4 months ago Infosecurity-magazine.com
CVE-2025-6087 - A Server-Side Request Forgery (SSRF) vulnerability was identified in the @opennextjs/cloudflare package. The vulnerability stems from an unimplemented feature in the Cloudflare adapter for Open Next, which allowed unauthenticated users to proxy ...
7 months ago
How to perform a proof of concept for automated discovery using Amazon Macie | AWS Security Blog - After reviewing the managed data identifiers provided by Macie and creating the custom data identifiers needed for your POC, it’s time to stage data sets that will help demonstrate the capabilities of these identifiers and better understand how ...
1 year ago Aws.amazon.com
Cloudflare Dashboard and APIs down after data center power outage - An ongoing Cloudflare outage has taken down many of its products, including the company's dashboard and related application programming interfaces customers use to manage and read service configurations. The complete list of services whose ...
2 years ago Bleepingcomputer.com
Cloudflare hit by data breach in SalesLoft, Drift supply chain attack - Cloudflare, a leading web infrastructure and security company, has recently been impacted by a significant data breach linked to a supply chain attack involving SalesLoft and Drift. This incident highlights the growing risks associated with ...
4 months ago Bleepingcomputer.com
Tech Security Year in Review - In this Tech Security Year in Review for 2023, let's look into the top data breaches of the past year. Each factor contributes to the growing threatscape, demanding a proactive and adaptable cybersecurity approach to safeguard your organization ...
2 years ago Securityboulevard.com
Polyfill.io, BootCDN, Bootcss, Staticfile attack traced to 1 operator - The recent large scale supply chain attack conducted via multiple CDNs, namely Polyfill.io, BootCDN, Bootcss, and Staticfile that affected anywhere from 100,000 to tens of millions of websites has been traced to a common operator, according to ...
1 year ago Bleepingcomputer.com
Salesloft confirms GitHub breach, Drift also impacted - Salesloft, a leading sales engagement platform, recently confirmed a security breach involving its GitHub repositories. The breach was discovered after suspicious activity was detected, leading to an investigation that revealed unauthorized access to ...
4 months ago Infosecurity-magazine.com
Cloudflare publishes details of Thanksgiving security breach The Register - Cloudflare has just detailed how suspected government spies gained access to its internal Atlassian installation using credentials stolen via a security breach at Okta in October. In a write-up on Thursday, CEO Matthew Prince, CTO John ...
1 year ago Go.theregister.com
Data Breach Response: A Step-by-Step Guide - In today's interconnected world, organizations must be prepared to respond swiftly and effectively in the face of a data breach. To navigate these challenges, a well-defined and comprehensive data breach response plan is essential. Let's explore the ...
1 year ago Securityzap.com
How to Arm Yourself With CloudFlare Security Solutions - Securing your website or digital asset is a critical part of running a successful business or website. With the rise of the digital era, the need to protect yourself from cyber-attacks is essential. That's why CloudFlare, the leading cloud solution ...
2 years ago Blog.cloudflare.com
Cloudflare mitigates record number of DDoS attacks in 2025 - Internet services giant Cloudflare says it mitigated a record number of DDoS attacks in 2024, recording a massive 358% year-over-year jump and a 198% quarter-over-quarter increase. However, 2025 is looking to be an even bigger problem for online ...
8 months ago Bleepingcomputer.com
Cloudflare hacked using auth tokens stolen in Okta attack - Cloudflare disclosed today that its internal Atlassian server was breached by a 'nation state' attacker who accessed its Confluence wiki, Jira bug database, and Atlassian Bitbucket source code management system. The threat actor first gained access ...
1 year ago Bleepingcomputer.com
Salesloft Breached After GitHub Account Compromise - Salesloft, a prominent sales engagement platform, recently disclosed a security breach resulting from a compromised GitHub account. The attackers gained unauthorized access to the company's internal systems by exploiting credentials linked to their ...
4 months ago Darkreading.com
The Ongoing Fallout From a Breach at AI Chatbot Maker Salesloft | Krebs on Security - In September 2025, Salesloft, a prominent AI chatbot maker, suffered a significant data breach that has since led to ongoing fallout affecting its operations and customers. The breach exposed sensitive information, raising concerns about the security ...
4 months ago Krebsonsecurity.com
Cloudflare R2 service outage caused by password rotation error - The absence of safeguards and validation checks for high-impact actions led to the outage, prompting Cloudflare to plan and implement additional measures for improved account provisioning, stricter access control, and two-party approval processes for ...
9 months ago Bleepingcomputer.com
Cloudflare Confirms Data Breach Affecting Customer Data - Cloudflare has officially confirmed a data breach that has impacted its customer data, raising significant concerns in the cybersecurity community. The breach involved unauthorized access to sensitive information, potentially exposing client details ...
4 months ago Cybersecuritynews.com
9 Best DDoS Protection Service Providers for 2024 - eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More. One of the most powerful defenses an organization can employ against distributed ...
2 years ago Esecurityplanet.com
Goto Customers Backup Data Breach: Protect Your Business and Handle Data Breach Risks - A data breach at Goto customers exposed their backup data to malicious actors, leading to a data breach that impacted those customers. Businesses need to be aware of the risks associated with data breaches and how to protect their organisations from ...
3 years ago Securityaffairs.com
Google warns SalesLoft breach impacted some Workspace accounts - Google has issued a warning regarding a security breach at SalesLoft that has affected some Google Workspace accounts. The incident highlights the risks associated with third-party integrations and the importance of robust security measures to ...
4 months ago Bleepingcomputer.com
Cloudflare says 1.1.1.1 outage not caused by attack or BGP hijack - To quash speculation of a cyberattack or BGP hijack incident causing the recent 1.1.1.1 Resolver service outage, Cloudflare explains in a post mortem that the incident was caused by an internal misconfiguration. Cloudflare also points out that the ...
6 months ago Bleepingcomputer.com
Welltok data breach exposes data of 8.5 million US patients - Healthcare SaaS provider Welltok is warning that a data breach exposed the personal data of nearly 8.5 million patients in the U.S. after a file transfer program used by the company was hacked in a data theft attack. Welltok works with health service ...
2 years ago Bleepingcomputer.com
Hackers Abuse Cloudflare Services for Sophisticated Phishing Attacks - The attacks, which began emerging in early 2025, leverage Cloudflare Workers and Pages to host malicious content that easily bypasses traditional security filters due to the trusted nature of Cloudflare’s infrastructure. Cybersecurity experts ...
9 months ago Cybersecuritynews.com
Russia’s throttling of Cloudflare makes sites inaccessible - "As the throttling is being applied by local ISPs, the action is outside of Cloudflare’s control, and we are unable, at this time, to restore reliable, high-performance access to Cloudflare products and protected websites for Russian users in a ...
6 months ago Bleepingcomputer.com