Wednesday, 1 Apr 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • ScienceAlert
  • White
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Watch
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > How attackers hit 700 organizations through CX platforms your SOC already approved
Tech and Science

How attackers hit 700 organizations through CX platforms your SOC already approved

Last updated: February 19, 2026 3:15 pm
Share
How attackers hit 700 organizations through CX platforms your SOC already approved
SHARE

CX platforms are revolutionizing customer experience by processing billions of unstructured interactions every year. From survey forms to social media feeds, these platforms use AI engines to automate workflows that touch various systems like payroll, CRM, and payment systems. However, a significant security gap exists in ensuring the integrity of the data being fed into these AI engines, allowing attackers to exploit vulnerabilities and cause widespread damage without deploying any malware.

The Salesloft/Drift breach in August 2025 serves as a stark example of this security loophole. Attackers compromised Salesloft’s GitHub environment, stole Drift chatbot OAuth tokens, and gained access to Salesforce environments across over 700 organizations, including major companies like Cloudflare, Palo Alto Networks, and Zscaler. They then scanned the stolen data for sensitive information like AWS keys, Snowflake tokens, and plaintext passwords, all without deploying any malware.

Despite the prevalence of data loss prevention (DLP) programs in organizations, only a mere 6% have dedicated resources to monitor and secure the data flowing into AI engines. This lack of oversight leaves organizations vulnerable to attacks that exploit legitimate access routes rather than traditional malware-based intrusions. Cloud intrusions have surged by 136% in the first half of 2025, highlighting the urgent need for improved security measures.

Experience management platforms like Qualtrics, which process billions of interactions annually, are no longer just ‘survey tools’ but integral components that connect to critical systems like HRIS, CRM, and compensation engines. Organizations must prioritize input integrity as AI technology becomes increasingly embedded in their workflows to prevent data breaches and unauthorized access.

See also  I Was Wrong About The iPhone Air - 5 Reasons You Should Buy It

Security leaders have identified six key blind spots that exist between the security stack and the AI engine in CX platforms:

1. DLP tools struggle to detect unstructured sentiment data leaving through standard API calls.
2. Zombie API tokens from past campaigns remain active, posing a security risk.
3. Public input channels lack bot mitigation, allowing fraudulent data to reach the AI engine undetected.
4. Compromised CX platforms enable lateral movement through approved API calls.
5. Non-technical users often hold admin privileges that go unchecked.
6. Open-text feedback containing sensitive information hits the database before PII gets masked, exposing vulnerabilities.

To address these vulnerabilities, organizations must implement continuous monitoring of user activity, configurations, and data access within experience management platforms. Security teams are exploring solutions like extending SSPM tools, API security gateways, and CASB-style access controls to enhance security measures in CX platforms.

By bridging the gap between security posture management and the CX layer, organizations can gain real-time visibility into potential threats and enforce policies to protect sensitive data effectively. It is crucial for security teams to prioritize the security of AI-driven workflows to prevent costly data breaches and ensure the integrity of business decisions made based on AI-generated insights.

TAGGED:ApprovedAttackershitorganizationsPlatformsSOC
Share This Article
Twitter Email Copy Link Print
Previous Article Megyn Kelly Defends Her Coverage of Nancy Guthrie’s Son-in-Law as a Suspect Megyn Kelly Defends Her Coverage of Nancy Guthrie’s Son-in-Law as a Suspect
Next Article Harris Reed Fall 2026 Ready-to-Wear Collection Harris Reed Fall 2026 Ready-to-Wear Collection
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts

Kendall Jenner Goes Incognito Mode in Paris

In today's celebrity landscape, public figures often attempt to evade the relentless attention of the…

October 2, 2025

New Epstein Island Images Reveal Signs Pedo ‘Was Also Serial Killer’

New Revelations in Jeffrey Epstein Case: Images of Violence and Fear Recently released images from…

December 5, 2025

Rat hordes causing chaos for California’s almond industry

If you're a fan of almond milk, you might want to consider switching to rice…

August 9, 2025

CNN’s News, Brought to You by T-Mobile in Aggressive Ad Deal

TV news shows are often sponsored, and now CNN is taking it a step further…

November 10, 2025

Subverting the Efforts of President Trump and Defense Secretary Hegseth to Restore the Military, At Least One Senior Official Appears to Have Made a Promise He Had No Intention to Keep |

Image: Wikimedia Commons (Photo by Sgt. 1st Class Michael Sword, U.S. Army) Chief Warrant Officer…

June 17, 2025

You Might Also Like

FDA Approves New Weight-Loss Pill That Can Be Taken Any Time of Day : ScienceAlert
Tech and Science

FDA Approves New Weight-Loss Pill That Can Be Taken Any Time of Day : ScienceAlert

April 1, 2026
Comprehensive Guide to Predictive Analytics in Retail
Tech and Science

Comprehensive Guide to Predictive Analytics in Retail

April 1, 2026
Secrets of color vision could hold clues to treating nearsightedness
Tech and Science

Secrets of color vision could hold clues to treating nearsightedness

April 1, 2026
Cameo partners with TikTok to boost popularity
Tech and Science

Cameo partners with TikTok to boost popularity

April 1, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?