Handshake Security Update: Salesforce Drift Incident
Protecting customer data and maintaining transparency are at the core of Handshake’s mission. We are committed to keeping customers informed about security developments that may affect their organization and want to share a detailed update regarding the recent Salesforce Drift incident.
What Happened?
On Wednesday, August 27, Handshake learned of a compromise involving a third-party application, Salesloft’s Drift, which resulted in unauthorized access and exfiltration of data stored in our Salesforce environment. Once notified, Handshake took immediate action to secure the environment, disconnecting the application from its Salesforce instance and launching a comprehensive investigation with our internal security team.
The impact of this event is confined to our Salesforce environment and did not implicate Handshake’s core products, services, systems, or infrastructure.
What Information May Be Affected?
Our investigation determined that the exposed data is limited to business contact information and specific Salesforce-related content, which includes:
- Customer (company) name
- Business address and contracting information
- The name, job title, business phone number, and company email address of the customer representative
What Did Handshake Do?
Handshake took immediate steps to secure our environment and mitigate risks:
- Disconnected and revoked Salesloft Drift’s access to Handshake’s Salesforce instance. Out of an abundance of caution, we also disconnected all integrations of Drift with other applications, such as Handshake’s core product, marketing portal, and other internal sales applications.
- Rotated relevant API access tokens to prevent further access.
- Initiated a full investigation into the scope and impact of the breach, working closely with Salesforce and external experts.
- Prioritized additional safeguards and protocol enhancements to prevent similar incidents in the future.
- Activated continuous monitoring for any potential exposure or misuse of exfiltrated data tied to the incident.
Handshake will continue to provide updates should any new developments arise.
What You Can Do
We recommend the following actions to ensure your security:
- Exercise caution with unsolicited emails, phone calls, or requests for sensitive information. Always verify the source and do not disclose passwords or payment information through unverified channels.
- All communications from Handshake will come from trusted, official channels. Our email outreach will always come from @joinhandshake.com. Handshake Support will never ask for authentication or authorization details via unsolicited outreach, phone, or SMS.
- Report any suspicious activity to security@joinhandshake.com.
Need Assistance or Have Questions?
Handshake’s Customer Success and Support teams are available to assist you through all regular support channels. You may also contact the Handshake Security team directly at security@joinhandshake.com.
Your trust is paramount to us. Thank you for your continued partnership with Handshake.