Data Breach Watch logoDBW
    Technology
    Medium
    investigation open
    Updated about 1 month ago

    Tenable Confirmsin Widespread Salesloft Supply-Chain Data Breach

    Key takeaways

    • Reports suggest a potential breach involving Tenable Confirmsin Widespread Salesloft Supply-Chain.
    • Discovered on March 5, 2026.
    • Possible data exposed: Name, Email Address, Phone Number, Job Title, Company Affiliation, CRM Data, Vulnerability Scan Metadata.
    • Affects individuals in: California, Texas, New York, Florida, Illinois, Pennsylvania, Ohio, Michigan, Georgia, North Carolina.
    • Confirmation level: Confirmed by company.

    Breach confirmed

    The Tenable Confirmsin Widespread Salesloft Supply-Chain breach is confirmed. If you may be affected, add your details below and we will take it from there.

    Detailed summary

    In March 2026, cybersecurity company Tenable confirmed it was a victim of a supply-chain attack that also affected other organizations using the sales engagement platform Salesloft. Tenable disclosed the incident on March 15, 2026, stating that an unauthorized user gained access to a segment of its customer information stored within its Salesforce instance through a vulnerability in the integration with Salesloft. The company also confirmed that its core products and the data within them remained secure. Salesloft experienced the supply-chain attack between March 5 and March 8, 2026, and confirmed data exfiltration from its production environment.

    The compromised data for Tenable customers included names, business email addresses, phone numbers, regional and location references associated with customer accounts, and subject lines and initial descriptions from support cases. For the broader Salesloft breach, data types included names, email addresses, phone numbers, job titles, company affiliations, and partial CRM data. Tenable specifically noted that cybersecurity-related contact lists and vulnerability scan metadata were affected. There is no evidence that SSN, passwords, financial data, or medical records were exposed. Tenable notified approximately 45,000 individuals, while the overall Salesloft breach affected about 1.2 million individuals.

    Details about data breaches can emerge over time, and notifications to affected individuals may be delayed. Tenable took immediate action to secure its systems by revoking and rotating potentially compromised credentials, disabling the vulnerable application, and hardening its Salesforce environment.

    Data possibly involved

    • Name
    • Email Address
      Increases risk of phishing attacks and account takeovers
    • Phone Number
      May be used for SIM swapping or targeted scam calls
    • Job Title
    • Company Affiliation
    • CRM Data
    • Vulnerability Scan Metadata

    Company Response Timeline

    Response Grade
    A

    Notified consumers within 30 days of discovery

    Breach Occurred

    Mar 5, 2026

    Company Discovered

    Mar 10, 2026

    Regulator Notified

    Apr 8, 2026

    Consumers Notified

    Mar 20, 2026

    5 days to discover
    10 days to notify consumers

    Breach Verification Status

    Reports Only

    Complete

    Initial dark web reports of potential breach

    Company Confirmed

    Current

    Company has acknowledged the breach

    Regulator Confirmed

    Confirmed by regulatory authorities

    Note: Breach verification can take time. Information may evolve as more details become available from companies and regulators.

    Case Status:
    Investigation Open

    We're actively investigating this case and seeking affected individuals.

    Were You Affected By This Breach?

    If you are a customer or have received a data breach notification, you may submit your information as part of our ongoing investigation. Submitting your information is free and does not obligate you.

    Were you in the Tenable Confirmsin Widespread Salesloft Supply-Chain breach? Check your email

    Free scan against known breach datasets. Then remove your info from data-broker sites with Data Shield.

    No signup required. 30-second scan. Your email is only stored if you opt into alerts.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Check Your Risk Level

    Answer a few questions to understand how this breach might affect you

    What should I do?

    Change your passwords

    Update passwords for the affected service and any accounts using the same password

    Enable two-factor authentication

    Add an extra layer of security to your accounts

    Monitor your accounts

    Watch for suspicious activity on your financial and online accounts

    Watch for phishing attempts

    Be cautious of emails or messages claiming to be from the affected company

    Consider a credit freeze

    Prevent unauthorized access to your credit report

    Scan your email for other exposures

    Check whether this address shows up in other known breaches. Free, no account.

    Get your info off data-broker sites

    Data Shield files removal requests with every broker that accepts an authorized agent, and gives you the exact link or letter for the brokers that only accept requests from you.

    See how Data Shield works

    Got a notice about this breach?

    Paste it into BreachBrief to see exactly what data was exposed, how serious it is, and what to do next.

    Protect yourself

    Share This Breach Alert

    Help friends and family who might be affected by sharing this breach information

    Are you a law firm investigating this breach?

    Get qualified claimant leads delivered directly to your CRM.

    Related breaches

    Stay informed about breaches like this one

    We'll notify you when new data breaches are reported. Free, no spam. Unsubscribe anytime.

    Free, no spam. Unsubscribe anytime.