Skip to main content

Salesloft Drift Supply Chain Attack

Rian avatar
Written by Rian
Updated over 2 weeks ago

Summary

Zeplin does not have exposure to this vulnerability.

Background

Between August 8 and August 18 2025, a vulnerability in a popular integration for Salesforce, resulted in widespread data theft from Salesforce customer instances. Customers of Zeplin rightly ask if Zeplin was vulnerable to this issue.

Zeplin Exposure

Although Zeplin uses Salesforce as a vendor, Zeplin does not use Salesloft Drift, and therefore there is no risk of exposure to this vulnerability through Zeplin.

Zeplin facilitates integrations with other service providers (a list of which is available at zeplin.io/subprocessors). An investigation of all vendors with any likelihood of access to our Salesforce instance has verified no vendor is or was exposed to this vulnerability.

Updates

This bulletin was last updated on 5 September 2025.

New information will be updated here if and when we discover more.

Did this answer your question?