← AppFolio

2025 AppFolio — Salesloft Drift–linked Salesforce CRM exposure (Aug)

2025 72.4K records affected Share on X

Data compromised

CRM-held prospect and customer PII including SSN-class fields per state-filed consumer notices

Technical writeup

Property-management software vendor AppFolio publicly notified roughly 72,444 U.S. individuals after determining that unauthorized queries hit a Salesforce org it reached through the compromised Salesloft Drift third-party integration between August 8 and August 18, 2025, with vendor notification August 22 and investigation closure in September. Regulatory sample letters (e.g., Washington and Vermont AG mirrors) cited possible exposure of names, addresses, dates of birth, and Social Security numbers; AppFolio disabled affected integrations and offered credit monitoring.

Root cause

Abuse of Salesloft Drift OAuth tokens against customer Salesforce CRM (supply-chain wave aligned with FINRA and peer-sector August–September 2025 disclosures)

References