Saturday, September 12, 2026

Tenable Data Breach Confirmed -Customer Contact Details Compromised

Tenable, a well-known cybersecurity company, has confirmed that it was affected by a recent large-scale data theft campaign. The attack targeted Salesforce and Salesloft Drift integrations, and Tenable was one of the organizations caught up in the incident.

The company stressed that while customer contact details were accessed, Tenable products and the data inside those products were not impacted.

According to Tenable, the breach involved unauthorized access to its Salesforce system. The exposed information included subject lines and short descriptions submitted by customers when opening support cases.

Additionally, standard business contact information, such as customer names, email addresses, phone numbers, and location details, was also accessed. At this point, the company stated there is no evidence that this information has been misused.

Immediate Actions Taken

In response to the discovery, Tenable quickly took a series of steps to protect its systems and customers’ data. These measures included:

  • Revoking and rotating all potentially compromised Salesforce, Drift, and related credentials.
  • Strengthening its Salesforce and connected environments to prevent further exploitation.
  • Completely disabling and removing the Salesloft Drift application from its Salesforce instance.
  • Applying known indicators of compromise shared by Salesforce and top cybersecurity experts.
  • Maintaining continuous monitoring of its Salesforce and other SaaS applications using Tenable’s own security technology.

The company said these measures were critical to stop further threats and to harden its internal systems moving forward.

Tenable emphasized its commitment to keeping customers informed at every step. Impacted customers were notified promptly after the incident was confirmed.

The company also recommended customers review proactive security guidance issued by Salesforce and cybersecurity experts to stay protected against similar threats.

Tenable highlighted that while the information exposed was business-related contact details, the safety and privacy of its customers remain a top priority.

The company said that it is continuing its investigation alongside industry experts to fully understand the impact and ensure all possible safeguards are in place.

For customers who may still have concerns, Tenable has assured round-the-clock availability of its support team.

Customers can reach out to Tenable directly at [email protected] for additional assistance and guidance.

In its statement, the cybersecurity firm emphasized that transparency and trust are fundamental to its mission.

“We remain committed to a thorough and open response to every security issue,” the company said. “Our teams are working tirelessly to safeguard our systems and protect our customers’ data.”

While investigations continue, Tenable reaffirms that no product-related or sensitive data held inside its security tools were impacted, and it will continue to share updates as needed.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data

Threat actors are increasingly using Claude-based AI workflows to...

China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks

China-linked threat actors UTA0560 and JungleBamboo chained a Google...

New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets

A newly identified phishing campaign is abusing the legitimate...

CISA Warns of Critical GitLab Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

Related Articles

Recent News