2025 JLL — Salesloft/Drift OAuth incident accessed Salesforce-held HR/Personal data (state notices)
Data compromised
HR/onboarding style PII enumerated in state template
Technical writeup
Massachusetts AG breach packet describes JLL notification for an Aug 2025 Salesloft vendor incident where OAuth abuse reached Salesforce objects storing names, contact, SSN, and DOB for affected individuals—representative of 2025 CRM supply-chain token theft wave.
Root cause
Third-party SaaS credential abuse against CRM integrations