Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Okta and Zscaler Respond to Salesloft Drift Security Breach
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Okta and Zscaler Respond to Salesloft Drift Security Breach

Highlights

  • Drift’s supply chain breach affected Okta, Zscaler, and hundreds more firms.

  • Okta evaded damage through IP restrictions; Zscaler faced customer data exposure.

  • Experts urge better API controls and token security after the incident.

Samantha Reed
Last updated: 6 October, 2025 - 1:19 pm 1:19 pm
Samantha Reed 5 hours ago
Share
SHARE

A supply chain attack targeting over 700 customers of the AI chatbot platform Drift has led to distinct responses from Okta and Zscaler, two leading cybersecurity providers. As organizations increasingly depend on software integrations, incidents like this highlight the tension between convenience and risk. Recent reports show that customer data related to Salesforce workflows became the focus of a coordinated campaign, exposing the security preparedness and response capabilities of companies heavily reliant on third-party vendors.

Contents
How Did Okta and Zscaler Discover the Threat?What Damage Occurred and How Did Companies Respond?Why Remain Unclear About the Source of the Attack?

Earlier reports noted that large-scale cybersecurity incidents involving OAuth token compromise are infrequent, but growing reliance on integrated SaaS applications has repeatedly introduced similar vulnerabilities in recent years. Previous incidents often focused on individual company vulnerabilities, while this case reveals the systemic risk inherent in interconnected platforms and APIs, elevating concerns about the widespread impact and necessity for improved identity and access management across the industry.

How Did Okta and Zscaler Discover the Threat?

Both Okta and Zscaler became aware of the threat through warnings from Google’s security team regarding drift-related anomalous activities. Okta’s security framework quickly identified and blocked unauthorized access attempts, leveraging pre-set IP address limitations on API activity. In contrast, Zscaler detected the breach only after Salesforce notified them, finding that their OAuth token for Drift, although unused since July, had already been exploited by the time they responded.

What Damage Occurred and How Did Companies Respond?

While Okta’s defensive measures prevented data compromise, Zscaler suffered exposure of customer and internal information, including business contact details and product licensing information. Zscaler immediately revoked the compromised token, but the incident revealed how even retired or soon-to-be deprecated tokens can remain a liability. The disparate outcomes demonstrate the significance of proactive monitoring and timely token rotation in mitigating security risks.

Why Remain Unclear About the Source of the Attack?

Salesloft’s investigation into the breach has not yet provided clarity on how unauthorized access to GitHub and Drift’s AWS environment was achieved. Both Okta and Zscaler have stated they lack information on the root mechanisms behind the token theft.

“I don’t actually know how they got the tokens out. I just know they did,”

said Sam Curry, Zscaler’s Chief Information Security Officer. David Bradbury, Okta’s Chief Security Officer, commented:

“The internet is connected by some very brittle, small pieces of information—these tokens that we constantly talk about.”

The analysis of these breaches underlines that current approaches to storing and protecting OAuth tokens may not adequately defend against mass collection or reuse by attackers. Both companies emphasized industry-wide responsibility—calling for vendors to prioritize security in their development processes, and for customers to demand stronger guarantees. Security leaders also expressed frustration over a lack of advanced countermeasures like tighter API controls and the implementation of Demonstrating Proof of Possession (DPoP) to link tokens to specific clients.

A deeper review of this breach and its aftermath illustrates recurring challenges for organizations extensively connected through APIs and cloud platforms. The persistent threat of supply chain attacks makes regular token rotation, IP-based API controls, and ongoing engagement with vendor security practices essential. Companies should audit their integrations, limit access based on necessity, and pressure SaaS providers to include advanced security features. Collaboration between affected entities, rather than assigning blame, is critical to raising the industry’s defensive posture and ensuring customer trust in a landscape defined by constant connectivity and evolving risks.

  • Drift’s supply chain breach affected Okta, Zscaler, and hundreds more firms.
  • Okta evaded damage through IP restrictions; Zscaler faced customer data exposure.
  • Experts urge better API controls and token security after the incident.
You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

Red Hat Reports Consulting Data Breach in GitLab System

Clop Demands Payment From Oracle Users via Targeted Emails

North Korean Operatives Target Firms Globally Through Remote Job Infiltration

Clop Ransomware Group Targets Oracle Users with Data Theft Threats

Security Experts Warn of Exploitation Risks in GoAnywhere MFT Flaw

Share This Article
Facebook Twitter Copy Link Print
Samantha Reed
By Samantha Reed
Samantha Reed is a 40-year-old, New York-based technology and popular science editor with a degree in journalism. After beginning her career at various media outlets, her passion and area of expertise led her to a significant position at Newslinker. Specializing in tracking the latest developments in the world of technology and science, Samantha excels at presenting complex subjects in a clear and understandable manner to her readers. Through her work at Newslinker, she enlightens a knowledge-thirsty audience, highlighting the role of technology and science in our lives.
Previous Article Tesla Teases Affordable Model Y Launch Next Monday
Next Article Tesla’s Record Q3 2025 Deliveries Drive Analyst Optimism

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Tesla’s Record Q3 2025 Deliveries Drive Analyst Optimism
Electric Vehicle
Tesla Teases Affordable Model Y Launch Next Monday
Electric Vehicle
Wordle Fans Solve ‘AMUSE’ Challenge as Game Maintains Popularity
Gaming
PayPal Mafia Drives Silicon Valley’s Expansion with New Ventures
Electric Vehicle Technology
Tesla Prepares to Reveal Major Project as Teaser Sparks Buzz
Electric Vehicle
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?