Desk live·
ForensicPost
Cloud/Supply chain/File 25-0826

Cloudflare Says 104 API Tokens Were Exposed via Pasted Support Cases

Cloudflare disclosed that 104 API tokens were exposed in the Salesloft incident, because customers and staff had pasted them into support cases. Ticket systems are unindexed secret stores.

Constructed geometry · not a chart of case data
JurisdictionUSASan Francisco, Californiathe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCloudflare case records
ActorUNC6395
D. Kennedy11 min readConfidence: high2 sources reviewed

In the Salesloft incident filed at 25-0818, attackers exported contact data, case records and — critically — API keys embedded in tickets and attachments. Cloudflare disclosed that 104 API tokens and sensitive case data were compromised, and rotated them.

This Is The Third Time This Database Has Filed The Same Thing

The EY compromise at 26-0713 turned on documents attached to IT support tickets. The Adobe claim at 26-0322 concerned 13 million support tickets. Here the tickets contained live credentials.

A support ticket exists to reproduce a problem, and reproducing an API problem means pasting the API call — with the token in it. Nobody decides to store secrets in a CRM; it happens one troubleshooting session at a time.

Why The Secret Scanning Everyone Deployed Does Not Catch This

Organisations have invested substantially in scanning source repositories for committed credentials, and that investment works. Almost nobody scans their support ticket system.

It is not classified as a place where code lives, so it falls outside the tooling’s scope — while accumulating exactly the same material, with a far broader internal readership and typically indefinite retention.

Disclosing The Number Is The Notable Behaviour

Publishing a specific count of exposed tokens is unusual. It invites the question of why they were there, which is not a flattering conversation.

It is also the thing that makes the incident useful to everyone else. A precise figure from a capable organisation is what turns "check your ticket system" from generic advice into a plausible estimate of what any peer would find.

How we reported this

Compiled from company disclosure and published research, listed below. The token count is the company’s own figure. See 25-0818 for the incident. Corrections: corrections@forensicpost.com.

Sources
  1. Reviewing the Salesforce–Salesloft Drift OAuth supply chain breachAnomali
  2. The Salesloft Drift breach: a cross-vendor lateral movement attackSilverfort
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary