Sunday, 21 Jun 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • White
  • ScienceAlert
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > How attackers hit 700 organizations through CX platforms your SOC already approved
Tech and Science

How attackers hit 700 organizations through CX platforms your SOC already approved

Last updated: February 19, 2026 3:15 pm
Share
How attackers hit 700 organizations through CX platforms your SOC already approved
SHARE

CX platforms are revolutionizing customer experience by processing billions of unstructured interactions every year. From survey forms to social media feeds, these platforms use AI engines to automate workflows that touch various systems like payroll, CRM, and payment systems. However, a significant security gap exists in ensuring the integrity of the data being fed into these AI engines, allowing attackers to exploit vulnerabilities and cause widespread damage without deploying any malware.

The Salesloft/Drift breach in August 2025 serves as a stark example of this security loophole. Attackers compromised Salesloft’s GitHub environment, stole Drift chatbot OAuth tokens, and gained access to Salesforce environments across over 700 organizations, including major companies like Cloudflare, Palo Alto Networks, and Zscaler. They then scanned the stolen data for sensitive information like AWS keys, Snowflake tokens, and plaintext passwords, all without deploying any malware.

Despite the prevalence of data loss prevention (DLP) programs in organizations, only a mere 6% have dedicated resources to monitor and secure the data flowing into AI engines. This lack of oversight leaves organizations vulnerable to attacks that exploit legitimate access routes rather than traditional malware-based intrusions. Cloud intrusions have surged by 136% in the first half of 2025, highlighting the urgent need for improved security measures.

Experience management platforms like Qualtrics, which process billions of interactions annually, are no longer just ‘survey tools’ but integral components that connect to critical systems like HRIS, CRM, and compensation engines. Organizations must prioritize input integrity as AI technology becomes increasingly embedded in their workflows to prevent data breaches and unauthorized access.

See also  Democrats Hit Rock Bottom! NBC Poll Shows Just 7% of Americans Have a ‘Very' Favorable Opinion of the Democrat Party |

Security leaders have identified six key blind spots that exist between the security stack and the AI engine in CX platforms:

1. DLP tools struggle to detect unstructured sentiment data leaving through standard API calls.
2. Zombie API tokens from past campaigns remain active, posing a security risk.
3. Public input channels lack bot mitigation, allowing fraudulent data to reach the AI engine undetected.
4. Compromised CX platforms enable lateral movement through approved API calls.
5. Non-technical users often hold admin privileges that go unchecked.
6. Open-text feedback containing sensitive information hits the database before PII gets masked, exposing vulnerabilities.

To address these vulnerabilities, organizations must implement continuous monitoring of user activity, configurations, and data access within experience management platforms. Security teams are exploring solutions like extending SSPM tools, API security gateways, and CASB-style access controls to enhance security measures in CX platforms.

By bridging the gap between security posture management and the CX layer, organizations can gain real-time visibility into potential threats and enforce policies to protect sensitive data effectively. It is crucial for security teams to prioritize the security of AI-driven workflows to prevent costly data breaches and ensure the integrity of business decisions made based on AI-generated insights.

TAGGED:ApprovedAttackershitorganizationsPlatformsSOC
Share This Article
Twitter Email Copy Link Print
Previous Article Megyn Kelly Defends Her Coverage of Nancy Guthrie’s Son-in-Law as a Suspect Megyn Kelly Defends Her Coverage of Nancy Guthrie’s Son-in-Law as a Suspect
Next Article Harris Reed Fall 2026 Ready-to-Wear Collection Harris Reed Fall 2026 Ready-to-Wear Collection
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.

Popular Posts

5 Key Takeaways From Berlin Fashion Week FW26

Berlin Fashion Week (BFW) is known for its extremes, and this season was no exception.…

February 3, 2026

Outlander Season 8 Release Date, Plot, Cast and Trailer

Outlander season 8 is on the horizon, marking the end of an era for fans…

July 30, 2025

Russia targets Ukrainian city on Palm Sunday

The recent Russian ballistic missile strike on the northeastern Ukrainian city of Sumy has resulted…

April 13, 2025

Dumbest Thing I’ve Seen a Player Wear on Court

Jalen Suggs, the young star of the Orlando Magic, made waves earlier this season with…

January 24, 2026

A Pretend Tea Party May Have Revealed a Chimp’s Imagination : ScienceAlert

New Study Suggests Apes Have Imagination: What This Means for Science NEW YORK (AP) –…

February 5, 2026

You Might Also Like

Polymarket reportedly paid creators to post deceptive videos about fake bets
Tech and Science

Polymarket reportedly paid creators to post deceptive videos about fake bets

June 21, 2026
We’ve found a mysterious substance on Titan and Pluto
Tech and Science

We’ve found a mysterious substance on Titan and Pluto

June 21, 2026
CTA train operator hit by flying glass as shootout erupts on Dan Ryan
Crime

CTA train operator hit by flying glass as shootout erupts on Dan Ryan

June 21, 2026
Ubisoft co-founder Claude Guillemot dies in plane crash
Tech and Science

Ubisoft co-founder Claude Guillemot dies in plane crash

June 21, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?