← Jones Lang LaSalle

2025 JLL — Salesloft/Drift OAuth incident accessed Salesforce-held HR/Personal data (state notices)

2025 Unknown records affected Share on X

Data compromised

HR/onboarding style PII enumerated in state template

Technical writeup

Massachusetts AG breach packet describes JLL notification for an Aug 2025 Salesloft vendor incident where OAuth abuse reached Salesforce objects storing names, contact, SSN, and DOB for affected individuals—representative of 2025 CRM supply-chain token theft wave.

Root cause

Third-party SaaS credential abuse against CRM integrations

References