Third-Party Security Incident Impacting Salesforce Integration via Drift
Final update
We have been informed of a security incident involving Drift, a third-party application previously integrated with our Salesforce environment as part of Cloudinary’s support processes. This incident is part of a broader issue affecting multiple organizations that use these services. Immediately upon learning of the situation, we disabled all connections between Cloudinary’s systems and Drift. We are actively working with Salesforce, Drift, and other relevant parties to support the ongoing investigation and to ensure the continued security of our data and systems. At this time, our review indicates that no data stored within Cloudinary’s products or core systems has been affected. The information involved appears limited to standard business contact details and certain support communications managed through Salesforce. Customers impacted by this incident have been notified directly with guidance and recommended next steps. As always, we encourage all customers to remain vigilant for any phishing or social engineering attempts that could result from incidents of this nature.
Timeline
- Resolved · Sep 3, 13:06 UTC
We have been informed of a security incident involving Drift, a third-party application previously integrated with our Salesforce environment as part of Cloudinary’s support processes. This incident is part of a broader issue affecting multiple organizations that use these services. Immediately upon learning of the situation, we disabled all connections between Cloudinary’s systems and Drift. We are actively working with Salesforce, Drift, and other relevant parties to support the ongoing investigation and to ensure the continued security of our data and systems. At this time, our review indicates that no data stored within Cloudinary’s products or core systems has been affected. The information involved appears limited to standard business contact details and certain support communications managed through Salesforce. Customers impacted by this incident have been notified directly with guidance and recommended next steps. As always, we encourage all customers to remain vigilant for any phishing or social engineering attempts that could result from incidents of this nature.
More from Cloudinary
Full history| Started | Incident | Impact | Duration |
|---|---|---|---|
| Aug 1317:04 UTC | Media Library / asset visibility | minor | 24h 41m |
| Jul 2913:35 UTC | Add-on installations are unavailable | minor | 1h 22m |
| Jul 2023:09 UTC | Connection failures with the Cloudinary MCP Connector | minor | 12h 16m |
| Jul 1410:17 UTC | Some customers experience authentication problems when accessing Cloudinary's Figma plugin | minor | 0m |
| Jul 1210:20 UTC | Elevated Error Rates for Requests Using g_auto | major | 2h 24m |
| Jun 1615:19 UTC | Delays in MediaFlows | minor | 15h 17m |
From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.