Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    5 ways to improve cybersecurity function while spending less

    August 27, 2025

    One-shot vaccines for HIV and covid

    August 27, 2025

    These Fields Are Losing the Most Entry-Level Jobs to AI: Study

    August 27, 2025
    Facebook X (Twitter) Instagram
    Trending
    • 5 ways to improve cybersecurity function while spending less
    • One-shot vaccines for HIV and covid
    • These Fields Are Losing the Most Entry-Level Jobs to AI: Study
    • AI super PACs, the hottest investment in tech
    • Snag this 85-inch Samsung QLED TV for less than $2,000 on Amazon
    • Fantasy football no longer belongs to the boys
    • T-Mobile will give you 4 free Google Pixel phones right now – here’s how the deal works
    • How procedural memory can cut the cost and complexity of AI agents
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Security»Attackers steal data from Salesforce instances via compromised AI live chat tool
    Security

    Attackers steal data from Salesforce instances via compromised AI live chat tool

    TechurzBy TechurzAugust 27, 2025No Comments1 Min Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Salesforce logo on building
    Share
    Facebook Twitter LinkedIn Pinterest Email


    The attackers executed SOQL queries to retrieve information associated with Salesforce objects such as Cases, Accounts, Users, and Opportunities and to extract data from them, after which they deleted the query jobs. However, the logs were not impacted so organizations can review their logs to determine what queries were executed and what data attackers stole.

    What Salesloft Drift users should do next

    The GTIG report and the Salesloft advisories include indicators of compromise such as IP addresses used by the attackers and User-Agent strings for the tools they used to access the data. Mandiant advises companies to also search logs for any activity from known Tor exit nodes in addition to the IP addresses listed in the IOCs and to open a Salesforce support ticket to receive a full list of queries executed by the attackers.

    Organizations should search their own Salesforce objects for any stored credentials and should rotate those, especially those containing the terms AKIA (AWS), Snowflake, password, secret and key. Strings related to organizational login URLs, including VPN and SSO pages should also be searched. An open-source tool called TruffleHog can also be used to search data for hardcoded secrets and credentials.

    attackers chat compromised data instances live Salesforce steal Tool
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleWhen’s the Best Time to Sell Your Business? Here’s What I Tell My Clients (And It’s Not When You Think)
    Next Article How procedural memory can cut the cost and complexity of AI agents
    Techurz
    • Website

    Related Posts

    Security

    5 ways to improve cybersecurity function while spending less

    August 27, 2025
    Security

    Snag this 85-inch Samsung QLED TV for less than $2,000 on Amazon

    August 27, 2025
    Security

    1.1M insurance customers were exposed in a data breach – here’s what to know

    August 27, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    You Can Now Get Starlink for $15-Per-Month in New York, but There’s a Catch

    July 11, 20257 Views

    Non-US businesses want to cut back on using US cloud systems

    June 2, 20257 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    You Can Now Get Starlink for $15-Per-Month in New York, but There’s a Catch

    July 11, 20257 Views

    Non-US businesses want to cut back on using US cloud systems

    June 2, 20257 Views
    Our Picks

    5 ways to improve cybersecurity function while spending less

    August 27, 2025

    One-shot vaccines for HIV and covid

    August 27, 2025

    These Fields Are Losing the Most Entry-Level Jobs to AI: Study

    August 27, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.