Salesforce Data Breach History
WebsiteSalesforce, Inc. is an American cloud-based software company. Fortune 500.
This page shows all data breaches of Salesforce. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.
Data Breach Timeline — All Salesforce Breaches
- 2026 2026 Salesforce ecosystem — ShinyHunters vishing wave against CRM tenants (platform context) Unknown records Share
- 2025 2025 Salesforce Agentforce "ForcedLeak" — prompt injection through Web-to-Lead exfiltrated CRM data Unknown records Share
- 2018 2018 — Cloud behemoth Salesforce.com is warning customers… Unknown records Share
Salesforce Data Breach Summary
This page tracks the Salesforce data breach history and cybersecurity incidents affecting Salesforce (United States). BreachHistory currently indexes 3 publicly disclosed or catalogued incidents spanning 2018 through 2026, with approximately an unknown number of records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.
The Salesforce breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed.
Largest Salesforce Data Breaches
Indexed Salesforce incidents are listed below. Where a public count is unavailable, the catalog shows unknown records exposed. Open each page for attack method, data types, and sources.
- 2026 2026 Salesforce ecosystem — ShinyHunters vishing wave against CRM tenants (platform context) — about Unknown records exposed · Catalogued incident
- 2025 2025 Salesforce Agentforce "ForcedLeak" — prompt injection through Web-to-Lead exfiltrated CRM data — about Unknown records exposed · Catalogued incident
- 2018 2018 — Cloud behemoth Salesforce.com is warning customers… — about Unknown records exposed · Catalogued incident
What Information Was Exposed?
Depending on the incident, exposed data may include email addresses, passwords, phone numbers, names, profile information, account identifiers, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.
Salesforce Data Breach 2026
At the time of this update, BreachHistory catalogues 1 2026 incident related to Salesforce. Most recent entry: 2026 Salesforce ecosystem — ShinyHunters vishing wave against CRM tenants (platform context). New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.
What To Do If You Were Affected
If you believe your account may have been involved in a Salesforce data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.
This Salesforce breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.