2025 Sprout Social — Salesloft Drift integration incident; Salesforce CRM exposure
Data compromised
Salesforce-held business contacts and related metadata per Sprout’s support article
Technical writeup
Sprout Social reported a September 12, 2025 incident in which unauthorized access via Salesloft’s Drift integration touched Sprout’s Salesforce CRM slice. According to the vendor notice, business contact fields (names, professional emails, phones, titles), light organizational attributes, and CRM metadata/summary fields could have been viewed, while core Sprout product datasets, credentials, payments, and helpdesk content were called out as out of scope. Sprout severed the integration, revoked tokens, and audited API credentials.
Root cause
Third-party SaaS integration compromise propagating into CRM OAuth access