2025 AppFolio — Salesloft Drift–linked Salesforce CRM exposure (Aug)
Data compromised
CRM-held prospect and customer PII including SSN-class fields per state-filed consumer notices
Technical writeup
Property-management software vendor AppFolio publicly notified roughly 72,444 U.S. individuals after determining that unauthorized queries hit a Salesforce org it reached through the compromised Salesloft Drift third-party integration between August 8 and August 18, 2025, with vendor notification August 22 and investigation closure in September. Regulatory sample letters (e.g., Washington and Vermont AG mirrors) cited possible exposure of names, addresses, dates of birth, and Social Security numbers; AppFolio disabled affected integrations and offered credit monitoring.
Root cause
Abuse of Salesloft Drift OAuth tokens against customer Salesforce CRM (supply-chain wave aligned with FINRA and peer-sector August–September 2025 disclosures)