Salesforce-Connected Third-Party Drift Application Supply Chain Incident Response
At Alteryx, we take the security of our customers and their data seriously. Our mission is to deliver trusted analytics solutions, and part of that commitment is keeping customers informed about security incidents that could impact their organization.
What Happened?
Alteryx was notified by Salesforce on August 22, 2025, of a security incident involving a third-party application, Drift (A Salesloft Product). The incident involved a threat actor using the Drift application’s integration with Salesforce to attempt to access customer CRM instances. However, the connection between Drift and Salesforce had already been terminated by Salesloft on August 20th as part of its response to the incident. This connection will remain disabled until the completion of our investigation, or until adequate assurances of security and safety have been provided by Salesloft and/or Salesforce.
Upon notice, Alteryx promptly began a detailed investigation with our Security Operations Center and Salesforce teams and confirmed unauthorized access to Alteryx’s Salesforce environment on or about August 13, 2025. A detailed analysis confirmed that Alteryx’s exposure was limited to a small sample of our Salesforce records and did not result in any confirmed loss of customer sensitive or confidential information. While the threat actor’s focus appeared to be on obtaining sensitive information, such as cloud access keys, credentials, and other secrets stored in case data, Alteryx’s sensitive information and that of its customers does not appear to have been accessed.
Findings
Based on our findings, the affected records included only business contact information of companies and individuals, publicly available information, notes on support cases (though not any attachments or files pertaining to such cases), and other non-sensitive business information used by Alteryx. We have confirmed that no Alteryx product environments or core systems were accessed through this incident, and we have not detected any further security irregularities following disabling the Drift connection.
Next steps
Alteryx will continue to work with Salesforce and monitor for indicators of suspect activity. We are also taking additional measures to ensure our Salesforce environment remains secure. If further investigation uncovers evidence of unauthorized access to sensitive information, we will directly notify impacted individuals and organizations commensurate with our contractual commitments and all relevant regulations.
What You Can Do
We recommend being cautious of unusual or unexpected communications that appear to come from Alteryx—for example, messages that request payment or change payment instructions.
If you have concerns about the authenticity of a communication purporting to originate from Alteryx, please contact us directly at security-notifications@alteryx.com or reach out to your Alteryx Account Representative.