In March 2026, cybersecurity company Tenable confirmed it was a victim of a supply-chain attack that also affected other organizations using the sales engagement platform Salesloft. Tenable disclosed the incident on March 15, 2026, stating that an unauthorized user gained access to a segment of its customer information stored within its Salesforce instance through a vulnerability in the integration with Salesloft. The company also confirmed that its core products and the data within them remained secure. Salesloft experienced the supply-chain attack between March 5 and March 8, 2026, and confirmed data exfiltration from its production environment.
The compromised data for Tenable customers included names, business email addresses, phone numbers, regional and location references associated with customer accounts, and subject lines and initial descriptions from support cases. For the broader Salesloft breach, data types included names, email addresses, phone numbers, job titles, company affiliations, and partial CRM data. Tenable specifically noted that cybersecurity-related contact lists and vulnerability scan metadata were affected. There is no evidence that SSN, passwords, financial data, or medical records were exposed. Tenable notified approximately 45,000 individuals, while the overall Salesloft breach affected about 1.2 million individuals.
Details about data breaches can emerge over time, and notifications to affected individuals may be delayed. Tenable took immediate action to secure its systems by revoking and rotating potentially compromised credentials, disabling the vulnerable application, and hardening its Salesforce environment.