Research Blogs Feed 09月29日
Zscaler数据安全事件说明
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Zscaler近日发现针对Salesloft Drift营销软件的攻击,导致大量客户OAuth令牌被盗。攻击者通过这些令牌有限访问了部分Zscaler Salesforce信息,包括业务联系人和CRM相关内容。Zscaler已迅速采取措施,包括撤销访问权限、旋转API令牌、加强安全协议,并建议客户提高警惕,防范钓鱼攻击。

🔒 攻击者通过盗窃Salesloft Drift的OAuth令牌,获得了对Zscaler Salesforce数据的有限访问权限,主要涉及业务联系人和CRM相关内容,包括姓名、邮箱、职位、电话等。

🚨 Zscaler已迅速响应,撤销了Salesloft Drift的访问权限,旋转了其他API令牌,并加强了安全协议,以防止类似事件再次发生。

🛡️ 建议客户保持高度警惕,防范钓鱼攻击或社会工程学尝试,对未经请求的通信保持谨慎,并始终验证通信来源,切勿通过非官方渠道泄露密码或财务信息。

At Zscaler, protecting your data and maintaining transparency are core to our mission to secure, simplify and accelerate businesses transformation. We are committed to keeping you informed about key developments that may impact your organization.What Happened?Zscaler was made aware of a campaign targeted at Salesloft Drift (marketing software-as-a-service) and impacting a large number of Salesloft customers. This incident involved the theft of OAuth tokens connected to Salesloft Drift, a third-party application used for automating sales workflows that integrates with Salesforce to manage leads and contact information. The scope of the incident is confined to Salesloft’s Drift app and does not involve access to any of Zscaler's products, services or underlying systems and infrastructure.As part of this campaign, unauthorized actors gained access to Salesloft Drift credentials of its customers including Zscaler. Following a detailed review as part of our ongoing investigation, we have determined that these credentials have allowed limited access to some Zscaler Salesforce information. What Information May Be Affected?The information accessed was limited to commonly available business contact details for points of contact and specific CRM related content, including:NamesBusiness email addressesJob titlesPhone numbersRegional/location detailsZscaler product licensing and commercial informationPlain text support case header content from certain cases limited to the following fields: Case Number, Opened, Preferred Contact Number, Description, Priority, Case Owner, Preferred Time Zone, Case Status, Type, Customer Case Reference, Product, Last Activity, Subject, Resolution Notes, Reason for Hand Off, Current Status / Next Plan of Action, Data Collected, Issue Summary / Business Impact, and Requestor. No attachments, files, or images were included in the incident, as it solely involved structured text data from case headers.After extensive investigation, Zscaler has currently found no evidence to suggest misuse of this information. If anything changes, we will provide further communications and updates. What Did Zscaler Do? Zscaler acted swiftly to address the incident and mitigate risks. Steps taken include:Revoking Salesloft Drift’s access to Zscaler’s Salesforce dataOut of an abundance of caution, rotating other API access tokens.Launching a detailed investigation into the scope of the event, working closely with Salesloft to assess and understand impacts as they continue investigating.Implementing additional safeguards and strengthening protocols to defend against similar incidents in the future.Immediately launched a third party risk management investigation for third party vendors used by Zscaler.Zscaler Customer Support team has further strengthened customer authentication protocol when responding to customer calls to safeguard against potential phishing attacks. What You Can DoAlthough the incident’s scope remains limited (as stated above) and no evidence of misuse has been found, we recommend that customers maintain heightened vigilance. Please be wary of potential phishing attacks or social engineering attempts, which could leverage exposed contact details.Given that other organizations have suffered similar incidents stemming from Salesloft Drift, it’s crucial to exercise caution regarding unsolicited communications, including emails, phone calls, or requests for sensitive information. Always verify the source of communication and never disclose passwords or financial data via unofficial channels.Zscaler Support will never request authentication or authorization details through unsolicited outreach, including phone calls or SMS. All official Zscaler communications come from trusted Zscaler channels. Please exercise caution and report any suspicious phishing activity to security@zscaler.com. Need Assistance or Have Questions?If you have concerns or need additional support, Zscaler’s Customer Success and Support teams are available via help.zscaler.com or your existing Zscaler support channels. You can also reach out to our Security team at driftincident@zscaler.com.Your security is our top priority. Thank you for your continued partnership with Zscaler.Update: Blog updated on September 3rd, 2025 to include support case information impacted by the incident. Blog updated on September 7th, 2025 to include additional support case information impacted by the incident.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Zscaler 数据安全 OAuth令牌 Salesloft Drift 钓鱼攻击
相关文章