Data – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Mon, 15 Sep 2025 07:24:51 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 Data – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 What is the best way to keep a sync *copy* of all Bitcoin core data on an external drive? https://earlybirdsinvest.com/what-is-the-best-way-to-keep-a-sync-copy-of-all-bitcoin-core-data-on-an-external-drive/ https://earlybirdsinvest.com/what-is-the-best-way-to-keep-a-sync-copy-of-all-bitcoin-core-data-on-an-external-drive/#respond Mon, 15 Sep 2025 07:24:50 +0000 https://earlybirdsinvest.com/what-is-the-best-way-to-keep-a-sync-copy-of-all-bitcoin-core-data-on-an-external-drive/

How do you always have it? Number 2 Copying Bitcoin core data (blocks, indexes, chain states) to an external drive?

Drives are connected to nodes only if they are not connected to individual offline workstations.

Ideally, there’s no need to stop bitcoind On a node at any point. So far I’ve been using this command:

rsync -P -h -a --delete /home/satoshi/.bitcoin/ /mnt/bitcoin-copy/

However, it can take a particularly long time after the drive has been disconnected for a while. More importantly, chain states take too long to synchronize and get damaged.

You will stop the node during copy corrections for that issue, but if possible, even a more bulletproof or automated solution. Is Raid 1 also an option in this scenario?

Thank you in advance!

]]>
https://earlybirdsinvest.com/what-is-the-best-way-to-keep-a-sync-copy-of-all-bitcoin-core-data-on-an-external-drive/feed/ 0 58518
FBI warns of UNC6040, UNC6395 hackers stealing Salesforce data https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/ https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/#respond Sun, 14 Sep 2025 22:57:24 +0000 https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/

FBI cyber

The FBI has issued a FLASH alert warning that two threat clusters, tracked as UNC6040 and UNC6395, are compromising organizations’ Salesforce environments to steal data and extort victims.

“The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate Indicators of Compromise (IOCs) associated with recent malicious cyber activities by cyber criminal groups UNC6040 and UNC6395, responsible for a rising number of data theft and extortion intrusions,” reads the FBI’s FLASH advisory.

“Both groups have recently been observed targeting organizations’ Salesforce platforms via different initial access mechanisms. The FBI is releasing this information to maximize awareness and provide IOCs that may be used by recipients for research and network defense.”

UNC6040 was first disclosed by Google Threat Intelligence (Mandiant) in June, who warned that since late 2024, threat actors were using social engineering and vishing attacks to trick employees into connecting malicious Salesforce Data Loader OAuth apps to their company’s Salesforce accounts.

In some cases, the threat actors impersonated corporate IT support personnel, who used renamed versions of the application called “My Ticket Portal.”

Once connected, the threat actors used the OAuth application to mass-exfiltrate corporate Salesforce data, which was then used in extortion attempts by the ShinyHunters extortion group.

In these early data theft attacks, ShinyHunters told BleepingComputer that they primarily targeted the “Accounts” and “Contacts” database tables, which are both used to store data about a company’s customers.

These data theft attacks were widespread, impacting large and well-known companies, such as Google, Adidas, Qantas, Allianz Life, Cisco, Kering, Louis Vuitton, Dior, and Tiffany & Co.

Later data theft attacks in August also targeted Salesforce customers, but this time utilized stolen Salesloft Drift OAuth and refresh tokens to breach customers’ Salesforce instances.

This activity is tracked as UNC6395 and is believed to have occurred between August 8th and 18th, with the threat actors using the tokens to target the company’s support case information that was stored in Salesforce.

The exfiltrated data was then analyzed to extract secrets, credentials, and authentication tokens shared in support cases, including AWS keys, passwords, and Snowflake tokens. These credentials could then be used to pivot to other cloud environments for additional data theft.

Salesloft worked with Salesforce to revoke all Drift tokens and required customers to reauthenticate to the platform.

It was later revealed that the threat actors also stole Drift Email tokens, which were used to access emails for a small number of Google Workspace accounts.

An investigation by Mandiant determined the attack originated in March, when Salesloft’s GitHub repositories were compromised, allowing attackers to ultimately steal the Drift OAuth tokens.

Like the previous attacks, these new Salesloft Drift data theft attacks impacted numerous companies,  including Cloudflare, Zscaler, Tenable, CyberArk, Elastic, BeyondTrust, Proofpoint, JFrog, Nutanix, Qualys, Rubrik, Cato Networks, Palo Alto Networks, and many more.

While the FBI did not name the groups behind these campaigns, BleepingComputer was told by the ShinyHunters extortion group that they and other threat actors calling themselves “Scattered Lapsus$ Hunters, were behind both clusters of activity.

This group of hackers claims to have originated from and overlap with the Lapsus$, Scattered Spider, and ShinyHunters extortion groups.

On Thursday, the threat actors announced via a domain associated with BreachForums that they planned to “go dark” and stop discussing operations on Telegram.

However, in a parting post, the hackers claimed to have gained access to the FBI’s E-Check background check system and Google’s Law Enforcement Request system, publishing screenshots as proof.

If legitimate, this access would allow them to impersonate law enforcement and pull sensitive records of individuals.

When contacted by BleepingComputer, the FBI declined to comment, and Google did not respond to our email.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/fbi-warns-of-unc6040-unc6395-hackers-stealing-salesforce-data/feed/ 0 58467
If any data is unavoidable, will deleting op_return limit shift demand to more harmful storage methods (such as UTXO inflation addresses)? https://earlybirdsinvest.com/if-any-data-is-unavoidable-will-deleting-op_return-limit-shift-demand-to-more-harmful-storage-methods-such-as-utxo-inflation-addresses/ https://earlybirdsinvest.com/if-any-data-is-unavoidable-will-deleting-op_return-limit-shift-demand-to-more-harmful-storage-methods-such-as-utxo-inflation-addresses/#respond Sun, 14 Sep 2025 04:18:32 +0000 https://earlybirdsinvest.com/if-any-data-is-unavoidable-will-deleting-op_return-limit-shift-demand-to-more-harmful-storage-methods-such-as-utxo-inflation-addresses/

Wouldn’t deleting OP_RETURN CAP unintentionally give users an incentive to choose the cheapest or most cost-deferred method?

Why is that happening? The limit does not make OP_RETURN more expensive, and if there is a limit it will make OP_RETURN cheaper, and the cost per byte of data is the same regardless of the limit. The increased limit is that OP_Return is more useful in situations where you want to add 80 bytes or more of data to the output. This is great for everyone as an output data substitute adds that data to the UTXO set.

Instead of treating all vectors equally, shouldn’t a policy try to manipulate the demand for any data for the “most harmful” output, like Op_return?

That’s what this policy actually does. It incentivizes people who store more than 80 bytes of data in the output. Otherwise, you’re using bare multisigs or multiple Taproot outputs to use good Op_return across your network.

]]>
https://earlybirdsinvest.com/if-any-data-is-unavoidable-will-deleting-op_return-limit-shift-demand-to-more-harmful-storage-methods-such-as-utxo-inflation-addresses/feed/ 0 58331
Bitcoin eyes $115K on CPI data as traders diverge on new BTC price dip https://earlybirdsinvest.com/bitcoin-eyes-115k-on-cpi-data-as-traders-diverge-on-new-btc-price-dip/ https://earlybirdsinvest.com/bitcoin-eyes-115k-on-cpi-data-as-traders-diverge-on-new-btc-price-dip/#respond Thu, 11 Sep 2025 15:38:43 +0000 https://earlybirdsinvest.com/bitcoin-eyes-115k-on-cpi-data-as-traders-diverge-on-new-btc-price-dip/

Key points:

  • Bitcoin nears three-week highs as US CPI data matches expectations.

  • Plenty of market participants see Bitcoin heading higher as aresult, perhaps after a dip to trap late longs.

  • CPI has seen BTC price fakeouts in recent months.

Bitcoin (BTC) saw telltale volatility at Thursday’s Wall Street open as US macro data furthered interest-rate cut odds.

BTC/USD one-hour chart. Source: Cointelegraph/TradingView

CPI bullseye sees calls for Bitcoin going “higher”

Data from Cointelegraph Markets Pro and TradingView showed BTC/USD spiking to $114,731.

The August print of the US Consumer Price Index (CPI) came in as expected, complementing a marked cooling of the Producer Price Index (PPI) the day prior.

US CPI 12-month % change. Source: US Bureau of Labor Statistics

While CPI was at its highest since January, the headline figure was instead initial jobless claims, which saw their largest numbers since October 2021 at 263,000 versus 235,000 expected.

Amid ongoing concerns about labor market weakness, bets of the Fed cutting rates at its Sept. 17 meeting only strengthened after the CPI release, with markets even seeing an 11% chance of the cut being more than the minimum 0.25%.

“Markets are now pricing-in 75 basis points of rate cuts by year-end,” trading resource The Kobeissi Letter noted in a follow-up thread on X. 

“While CPI inflation continues to rise, the labor market is simply too weak to ignore. Next week will be a big week.”

Fed target rate probabilities (screenshot). Source: CME Group FedWatch Tool

Crypto commentators saw the case for higher prices next as Bitcoin passed $114,500 for the first time since Aug. 24.

“PPI much lower than expected, CPI as expected,” popular trader Jelle responded in an X post. 

“Conclusion: Inflation not as bad as expected – bring on the rate cut later this month. News now behind us, time to resume the scheduled programme: higher.”

BTC price risks repeating US inflation data trap

BTC price forecasts also stressed the importance of recent support reclaims.

Related: Bitcoin price can hit $160K in October as MACD golden cross returns

For fellow trader BitBull, flipping $113,500 from resistance to support was the key low-time frame event, which opened the door to a rematch with all-time highs.

Some perspectives nonetheless saw a fresh support retest coming before a return to price discovery.

Trader Skew argued that the market would attempt to trap and liquidate longs that entered on the CPI release.

“One more liquidation before higher,” part of an X post suggested, noting 2,000 BTC of liquidity appearing on exchange order books.

BTC/USDT order-book liquidity data. Source: Skew/X

Crypto investor and entrepreneur Ted Pillows went further, suggesting that BTC/USD would copy previous CPI behavior to first rise then plumb fresh lows.

“In the last 3 CPI data releases, Bitcoin rallied before CPI data and dumped right after the data release,” he observed alongside an explanatory chart. 

“This time, BTC has rallied before today’s CPI data release, which means a dump could happen.”

BTC/USDC one-day chart. Source: Ted Pillows/X

This article does not contain investment advice or recommendations. Every investment and trading move involves risk, and readers should conduct their own research when making a decision.

]]>
https://earlybirdsinvest.com/bitcoin-eyes-115k-on-cpi-data-as-traders-diverge-on-new-btc-price-dip/feed/ 0 57917
How can I include any data when using UTXO while enabling transactions? https://earlybirdsinvest.com/how-can-i-include-any-data-when-using-utxo-while-enabling-transactions/ https://earlybirdsinvest.com/how-can-i-include-any-data-when-using-utxo-while-enabling-transactions/#respond Thu, 11 Sep 2025 13:13:28 +0000 https://earlybirdsinvest.com/how-can-i-include-any-data-when-using-utxo-while-enabling-transactions/

When unlocking UTXO, I would like to include random (actually random 🙂) data.

I want to secure my spending with classic signatures.

At first I thought about using it p2wpkhbut from what I understand, a witness must contain exactly two elements (signature and public key). If there are more, the transaction is invalid.

1. Would I fix it?

After that I considered using the classic p2pkhwhere is it? scriptsig You can add data first before the signature and public key (for example, a simple 20-byte push). This should preserve security as only top-level stack elements are checked after the script is executed. Therefore, additional data does not cause any problems.

2. Would you like to fix it?

However, this is fine from a consensus and security perspective, but we also found that policy rules prevent such transactions from being relayed across the network, as multiple elements remain in the stack.

3. Would you like to fix it?

It’s very important to include additional data when using your funds, but I don’t know how to do this. Any ideas? Maybe we’ll use other transaction types to achieve this?

Any help is greatly appreciated. Please answer just one of the above questions.

]]>
https://earlybirdsinvest.com/how-can-i-include-any-data-when-using-utxo-while-enabling-transactions/feed/ 0 57902
Employment data revision washes $60B from crypto market cap https://earlybirdsinvest.com/employment-data-revision-washes-60b-from-crypto-market-cap/ https://earlybirdsinvest.com/employment-data-revision-washes-60b-from-crypto-market-cap/#respond Wed, 10 Sep 2025 00:14:30 +0000 https://earlybirdsinvest.com/employment-data-revision-washes-60b-from-crypto-market-cap/

The crypto market lost $60 billion in market capitalization during the two hours following revised employment data, revealing a significantly weaker US labor market than previously reported.

The Bureau of Labor Statistics (BLS) announced at 10 AM ET on Sept. 9 that preliminary benchmark revisions showed total nonfarm employment was overstated by 911,000 jobs, representing a 0.6% downward revision from March 2024 to March 2025.

Bitcoin dropped 1.8% from $112,788.75 to $110,793.69 between 10 A.M. and 11 P.M. ET. Ethereum declined 1.6% from $4,346.56 to $4,277.17 during the same period.

Major altcoins posted steeper losses, with Dogecoin falling 4.1% from $0.2469 to $0.2367 and Solana dropping 3% from $218.04 to $211.69.

Other notable declines included Cardano’s 3.5% fall from $0.8839 to $0.8525, XRP’s 2.5% drop from $3.01 to $2.93, and BNB’s 1% decrease from $879.89 to $871.38.

Despite partial recoveries from daily lows, all assets remained below their pre-announcement prices.

Significant revision

Treasury Secretary Scott Bessent characterized the revision as confirmation that economic conditions were worse than reported, stating the data brought total job overstatements to 1.5 million when combined with previous downward revisions of 577,000.

Bessent argued that the Fed maintained a restrictive monetary policy based on inflated employment figures. The market reaction reflected investor concerns that the Federal Reserve operated with incomplete data when setting interest rate policy throughout 2024.

The substantial employment overcount suggested the economy required more accommodative monetary conditions earlier than policymakers recognized.

The annual benchmark revision process compares Current Employment Statistics estimates against comprehensive employment counts from the Quarterly Census of Employment and Wages, which derives data from state unemployment insurance tax records filed by nearly all employers.

The 0.6% revision magnitude exceeds the 10-year absolute average of 0.2%, highlighting the scale of the employment overcount. The BLS attributed the discrepancy to businesses reporting lower employment to unemployment insurance records than to monthly employment surveys.

The correction indicated traders view the current landscape as uncertain, although the revised numbers raise the odds of a rate cut in September.

Mentioned in this article
Posted In: Bitcoin, Cardano, Dogecoin, Ethereum, Solana, XRP, US, Adoption, Analysis, Crypto, Featured, Market
]]>
https://earlybirdsinvest.com/employment-data-revision-washes-60b-from-crypto-market-cap/feed/ 0 57630
The data came in rough… but it's bullish for crypto? https://earlybirdsinvest.com/the-data-came-in-rough-but-its-bullish-for-crypto/ https://earlybirdsinvest.com/the-data-came-in-rough-but-its-bullish-for-crypto/#respond Tue, 09 Sep 2025 20:31:48 +0000 https://earlybirdsinvest.com/the-data-came-in-rough-but-its-bullish-for-crypto/

Imagine you hack into the account of an NPM developer.

For those who aren’t tech nerds: NPM is basically the app store for programmers. It’s where they get chunks of pre-written code (called packages) to help them build websites and apps faster.

Now, this particular dev created some code so popular it gets downloaded over 2 BILLION times every week. That code’s inside tons of apps and sites you prolly use every day. Companies rely on it constantly without even thinking about it.

So, breaking into that account means you could slip malware right into their package. And since millions of apps automatically get the latest version of that code, your nasty surprise would spread everywhere.

It’s like poisoning the city’s water supply instead of just one bottle.

This would arguably be the largest supply chain hack in history – access to millions of computers, billions in potential damage, and entire companies in your hands.

And the crazy part: someone actually pulled this off.

Robert Pattinson shocked

“Holy. Sh*t 😦 This person’s gotta be a billionaire now, right?” – you, maybe.

… Not even close.

Bro walked away with less than $50.

Yes, I’m being for real. Five cents worth of Ethereum and about $20 of some random memecoin that barely anyone trades.

Kinda like breaking into a bank and leaving with a couple of coins you found under the couch cushions.

This failure was mainly due to the attacker’s mistakes, which led to early detection.

In the end, as the Security Alliance put it, the real cost is all the cleanup: thousands of hours burned by engineers and security teams worldwide, plus millions in new security contracts that companies will sign just because of this mess.

Either way, ughh, there’s something so satisfying about watching the bad guys flop ❤

]]>
https://earlybirdsinvest.com/the-data-came-in-rough-but-its-bullish-for-crypto/feed/ 0 57606
TRON Selected by U.S. Commerce Department for GDP Data Publication as Network Adoption Surges After 60% Fee Reduction https://earlybirdsinvest.com/tron-selected-by-u-s-commerce-department-for-gdp-data-publication-as-network-adoption-surges-after-60-fee-reduction/ https://earlybirdsinvest.com/tron-selected-by-u-s-commerce-department-for-gdp-data-publication-as-network-adoption-surges-after-60-fee-reduction/#respond Wed, 03 Sep 2025 06:47:58 +0000 https://earlybirdsinvest.com/tron-selected-by-u-s-commerce-department-for-gdp-data-publication-as-network-adoption-surges-after-60-fee-reduction/

Disclosure: This is a sponsored post. Readers should conduct further research prior to taking any actions. Learn more ›

September 2, 2025 – Geneva, Switzerland – TRON DAO, the community-governed DAO dedicated to accelerating the decentralization of the internet through blockchain technology and decentralized applications (dApps), announced today that the U.S. Department of Commerce has selected the TRON blockchain as one of the primary networks for posting official economic data, beginning with the second quarter gross domestic product (GDP) release.

For the first time, a federal agency has published official GDP data to public blockchains, demonstrating how decentralized technology can safeguard transparency and provide global access to critical economic indicators. The Bureau of Economic Analysis (BEA) reported a Q2 2025 GDP growth rate of 3.3 percent on an annualized basis, with the data hash recorded immutably on TRON with the transaction hash: 3f05633fb894aa6d6610c980975cca732a051edbbf5d8667799782cf2ae04040.

TRON’s Role in Securing U.S. Economic Data

The Department of Commerce recorded the SHA256 hash of the official GDP release on TRON, acknowledging the network’s proven ability to deliver scale, speed, efficiency, and global accessibility. Processing over $22 billion in daily settlement and more than 8.8 million daily transactions, TRON has emerged as a trusted layer of infrastructure not only for financial markets but also for the secure publication of government data worldwide.

“Publishing GDP data on chain is a powerful statement about the role TRON now plays as public infrastructure, not only for payments but for safeguarding some of the world’s most important information,” said Justin Sun, Founder of TRON. “This initiative shows how blockchain can advance transparency and trust in ways that strengthen both traditional institutions and decentralized systems. It is only the beginning of how public blockchains like TRON will redefine global access to data and finance.”

Publishing the GDP data hash on TRON highlights the role of decentralized networks in preserving data integrity, strengthening accountability, and ensuring open access for citizens, researchers, and policymakers worldwide. It also reflects the United States government’s commitment to leadership in blockchain innovation and to advancing America’s position as the global hub for digital trust and transparency.

In August 2025, TRON’s community governance approved a 60 percent reduction in energy fees, sharply lowering transaction costs and immediately driving adoption. Within days, TRON surpassed 2.5 million daily active users, overtaking both BNB Chain and Solana in activity, according to DeFiLlama data. The move was designed to preserve accessibility, particularly for stablecoin transfers, where TRON leads globally with more than $79 billion in USDT circulating on the network. 

Through its continued commitment to affordability and accessibility, TRON is establishing the foundation for enduring growth and securing its position as a vital infrastructure for the future of the global digital economy.

About TRON DAO

TRON DAO is a community-governed DAO dedicated to accelerating the decentralization of the internet via blockchain technology and dApps.

Founded in September 2017 by H.E. Justin Sun, the TRON blockchain has experienced significant growth since its MainNet launch in May 2018. Until recently, TRON hosted the largest circulating supply of USD Tether (USDT) stablecoin, which currently exceeds $79 billion. As of September 2025, the TRON blockchain has recorded over 329 million in total user accounts, more than 11 billion in total transactions, and over $28 billion in total value locked (TVL), based on TRONSCAN. Recognized as the global settlement layer for stablecoin transactions and everyday purchases with proven success, TRON is “Moving Trillions, Empowering Billions.”

TRONNetwork | TRONDAO | X | YouTube | Telegram | Discord | Reddit | GitHub | Medium | Forum

Media Contact
Yeweon Park
[email protected]

Mentioned in this article
]]>
https://earlybirdsinvest.com/tron-selected-by-u-s-commerce-department-for-gdp-data-publication-as-network-adoption-surges-after-60-fee-reduction/feed/ 0 56510
Chainlink Surges 3% to $24 After U.S. Government Data Partnership and Bitwise ETF Filing https://earlybirdsinvest.com/chainlink-surges-3-to-24-after-u-s-government-data-partnership-and-bitwise-etf-filing/ https://earlybirdsinvest.com/chainlink-surges-3-to-24-after-u-s-government-data-partnership-and-bitwise-etf-filing/#respond Wed, 03 Sep 2025 04:06:44 +0000 https://earlybirdsinvest.com/chainlink-surges-3-to-24-after-u-s-government-data-partnership-and-bitwise-etf-filing/

Chainlink (LINK) surged 3% to trade around $24 on Monday, marking a beginning of a strong performance in September despite a broadly cautious crypto market.

Related Reading

The rally was fueled by two significant announcements: a landmark U.S. government partnership to publish macroeconomic data on-chain and Bitwise’s filing for a spot Chainlink ETF with the SEC.

The U.S. Department of Commerce confirmed that the Bureau of Economic Analysis (BEA) will now release critical indicators such as GDP growth and the PCE Price Index directly across blockchain ecosystems like Ethereum, Arbitrum, and Optimism.

Chainlink’s Cross-Chain Interoperability Protocol (CCIP), which already handled $130 million in transfers this week, will play a vital role in ensuring data reliability across networks.

Government Data Goes On-Chain

The ETF move positions Chainlink at the forefront of blockchain adoption by governments. Commerce Secretary Howard Lutnick believes that the decision indicates America’s growing commitment to digital innovation, noting that the first on-chain data point published was a 3.3% GDP growth figure.

Analysts believe the integration of government data could revolutionize sectors ranging from automated trading strategies to decentralized finance (DeFi) risk management.

Mike Cahill, founder of Douro Labs and a core contributor to Pyth Network, called the initiative “a new wave of transparency and innovation.

By bringing trusted government data on-chain, Chainlink strengthens its role as a backbone for blockchain-based financial products, real-time prediction markets, and tokenized asset platforms.

Chainlink LINK LINKUSD

LINK's price trends to the upside on the daily chart. Source: LINKUSD on Tradingview

Chainlink (LINK) Price Forecast

From a technical perspective, Chainlink’s price action shows bullish momentum building near resistance levels. The token rebounded from $23 support last weekend and is now testing the $23.50–$24 resistance zone. A successful breakout above $25.50 could open the door for targets at $27.20 and $29.50, aligning with February’s highs.

However, analysts caution that a failure to hold above $24.20 may weaken the short-term outlook, potentially pushing LINK back toward the $23.00 support area. Still, with institutional interest rising after Bitwise’s ETF filing and government adoption underway, sentiment around Chainlink remains notably bullish.

Related Reading

As one of the few altcoins outperforming in a market weighed down by Bitcoin’s pullback, Chainlink’s latest surge may be a sign of growing resilience, and possibly the start of a larger breakout.

Cover image from ChatGPT, LINKUSD on Tradingview

]]>
https://earlybirdsinvest.com/chainlink-surges-3-to-24-after-u-s-government-data-partnership-and-bitwise-etf-filing/feed/ 0 56495
Cloudflare hit by data breach in Salesloft Drift supply chain attack https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/ https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/#respond Tue, 02 Sep 2025 21:07:53 +0000 https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/

Cloudflare

Cloudflare is the latest company impacted in a recent string of Salesloft Drift breaches, part of a supply-chain attack disclosed last week.

The internet giant revealed on Tuesday that the attackers gained access to a Salesforce instance it uses for internal customer case management and customer support, which contained 104 Cloudflare API tokens.

Cloudflare was notified of the breach on August 23, and it alerted impacted customers of the incident on September 2. Before informing customers of the attack, it also rotated all 104 Cloudflare platform-issued tokens exfiltrated during the breach, even though it has yet to discover any suspicious activity linked to these tokens.

“Most of this information is customer contact information and basic support case data, but some customer support interactions may reveal information about a customer’s configuration and could contain sensitive information like access tokens,” Cloudflare said.

“Given that Salesforce support case data contains the contents of support tickets with Cloudflare, any information that a customer may have shared with Cloudflare in our support system—including logs, tokens or passwords—should be considered compromised, and we strongly urge you to rotate any credentials that you may have shared with us through this channel.”

The company’s investigation found that the threat actors stole only the text contained within the Salesforce case objects (including customer support tickets and their associated data, but no attachments) between August 12 and August 17, after an initial reconnaissance stage on August 9.

These exfiltrated case objects contained only text-based data, including:

  • The subject line of the Salesforce case
  • The body of the case (which may include keys, secrets, etc., if provided by the customer to Cloudflare)
  • Customer contact information (for example, company name, requester’s email address and phone number, company domain name, and company country)

“We believe this incident was not an isolated event but that the threat actor intended to harvest credentials and customer information for future attacks,” Cloudflare added.

“Given that hundreds of organizations were affected through this Drift compromise, we suspect the threat actor will use this information to launch targeted attacks against customers across the affected organizations.”

Wave of Salesforce data breaches

Since the start of the year, the ShinyHunters extortion group has been targeting Salesforce customers in data theft attacks, using voice phishing (vishing) to trick employees into linking malicious OAuth apps with their company’s Salesforce instances. This tactic enabled the attackers to steal databases, which were later used to extort victims.

Since Google first wrote about these attacks in June, numerous data breaches have been linked to ShinyHunters’ social engineering tactics, including those targeting Google itself, Cisco, Qantas, Allianz Life, Farmers Insurance, Workday, Adidas, as well as LVMH subsidiaries Louis Vuitton, Dior, and Tiffany & Co.

While some security researchers have told BleepingComputer that the Salesloft supply chain attacks involve the same threat actors, Google has found no conclusive evidence linking them.

Palo Alto Networks also confirmed over the weekend that the threat actors behind the Salesloft Drift breaches stole some support data submitted by customers, including contact info and text comments.

The Palo Alto Networks incident was also limited to its Salesforce CRM and, as the company told BleepingComputer, it did not affect any of its products, systems, or services.

The cybersecurity company observed the attackers searching for secrets, including AWS access keys (AKIA), VPN and SSO login strings, Snowflake tokens, as well as generic keywords such as “secret,” “password,” or “key,” which could be used to breach more cloud platforms to steal data in other extortion attacks.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/cloudflare-hit-by-data-breach-in-salesloft-drift-supply-chain-attack/feed/ 0 56444