2025 Docebo — third-party CRM integration compromise (Aug); LMS out of scope per vendor
Data compromised
Business contacts, billing metadata, and CRM-ticket text per Docebo regulatory disclosure summaries
Technical writeup
Docebo customer notifications summarized in community threads and its 2025 Annual Information Form described August 13–18, 2025 unauthorized use of API tokens for a marketing/CRM integration separate from the core LMS and support-case stack. Vendor messaging framed exposure as business contact, billing, and limited support-ticket narrative fields without learner password or government-ID compromise; forums debated interpretation of “support ticket content” versus help-center systems.
Root cause
Third-party engagement/CRM connector token theft consistent with broader Salesloft-Drift–style Salesforce attacks reported the same month across vendors