Wednesday, 11 Mar 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • ScienceAlert
  • VIDEO
  • White
  • man
  • Trumps
  • Season
  • Watch
  • star
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > How attackers hit 700 organizations through CX platforms your SOC already approved
Tech and Science

How attackers hit 700 organizations through CX platforms your SOC already approved

Last updated: February 19, 2026 3:15 pm
Share
How attackers hit 700 organizations through CX platforms your SOC already approved
SHARE

CX platforms are revolutionizing customer experience by processing billions of unstructured interactions every year. From survey forms to social media feeds, these platforms use AI engines to automate workflows that touch various systems like payroll, CRM, and payment systems. However, a significant security gap exists in ensuring the integrity of the data being fed into these AI engines, allowing attackers to exploit vulnerabilities and cause widespread damage without deploying any malware.

The Salesloft/Drift breach in August 2025 serves as a stark example of this security loophole. Attackers compromised Salesloft’s GitHub environment, stole Drift chatbot OAuth tokens, and gained access to Salesforce environments across over 700 organizations, including major companies like Cloudflare, Palo Alto Networks, and Zscaler. They then scanned the stolen data for sensitive information like AWS keys, Snowflake tokens, and plaintext passwords, all without deploying any malware.

Despite the prevalence of data loss prevention (DLP) programs in organizations, only a mere 6% have dedicated resources to monitor and secure the data flowing into AI engines. This lack of oversight leaves organizations vulnerable to attacks that exploit legitimate access routes rather than traditional malware-based intrusions. Cloud intrusions have surged by 136% in the first half of 2025, highlighting the urgent need for improved security measures.

Experience management platforms like Qualtrics, which process billions of interactions annually, are no longer just ‘survey tools’ but integral components that connect to critical systems like HRIS, CRM, and compensation engines. Organizations must prioritize input integrity as AI technology becomes increasingly embedded in their workflows to prevent data breaches and unauthorized access.

See also  Ex-MLB pitcher Matt Bush hit with DWI charges after allegedly trying to flee car crash

Security leaders have identified six key blind spots that exist between the security stack and the AI engine in CX platforms:

1. DLP tools struggle to detect unstructured sentiment data leaving through standard API calls.
2. Zombie API tokens from past campaigns remain active, posing a security risk.
3. Public input channels lack bot mitigation, allowing fraudulent data to reach the AI engine undetected.
4. Compromised CX platforms enable lateral movement through approved API calls.
5. Non-technical users often hold admin privileges that go unchecked.
6. Open-text feedback containing sensitive information hits the database before PII gets masked, exposing vulnerabilities.

To address these vulnerabilities, organizations must implement continuous monitoring of user activity, configurations, and data access within experience management platforms. Security teams are exploring solutions like extending SSPM tools, API security gateways, and CASB-style access controls to enhance security measures in CX platforms.

By bridging the gap between security posture management and the CX layer, organizations can gain real-time visibility into potential threats and enforce policies to protect sensitive data effectively. It is crucial for security teams to prioritize the security of AI-driven workflows to prevent costly data breaches and ensure the integrity of business decisions made based on AI-generated insights.

TAGGED:ApprovedAttackershitorganizationsPlatformsSOC
Share This Article
Twitter Email Copy Link Print
Previous Article Megyn Kelly Defends Her Coverage of Nancy Guthrie’s Son-in-Law as a Suspect Megyn Kelly Defends Her Coverage of Nancy Guthrie’s Son-in-Law as a Suspect
Next Article Harris Reed Fall 2026 Ready-to-Wear Collection Harris Reed Fall 2026 Ready-to-Wear Collection
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts

The One Big Beautiful Bill Slashes Deficits, National Debt While Unleashing Economic Growth – The White House

President Trump’s ambitious economic strategy, prominently featuring the landmark One Big Beautiful Bill, is poised…

June 30, 2025

Bill Clinton Hospitalized With Flu, Influenza A Surges Throughout U.S.

This means that these droplets can travel up to six feet when someone coughs, sneezes,…

December 26, 2024

MoMA PS1 Reveals Greater New York Curators

Art Movements is a weekly roundup of news, appointments, awards, and other happenings in the…

November 13, 2025

Ukraine Ceasefire Deal Relies on Critical Minerals That Will Be Difficult to Access

The recent negotiations between Ukraine and the U.S. have shed light on Ukraine's mineral wealth…

March 12, 2025

Kacey Musgraves’ Dog Bit By Snake After Coming to Her Rescue 

Country music star Kacey Musgraves recently shared a heartwarming story about her loyal companion, Pepper,…

October 29, 2024

You Might Also Like

Chinese brain interface startup Gestala raises M just two months after launch
Tech and Science

Chinese brain interface startup Gestala raises $21M just two months after launch

March 11, 2026
A Simple Drink Choice Helps Gamers Stay Focused For Hours, Study Finds : ScienceAlert
Tech and Science

A Simple Drink Choice Helps Gamers Stay Focused For Hours, Study Finds : ScienceAlert

March 11, 2026
Iran was nowhere close to a nuclear bomb, experts say
Tech and Science

Iran was nowhere close to a nuclear bomb, experts say

March 11, 2026
King penguins are thriving in a warmer climate, but it may not last
Tech and Science

King penguins are thriving in a warmer climate, but it may not last

March 11, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?