Salesforce confirmed on July 13 2026 that a breach on July 12 exposed 1.1 million CRM records. Attackers accessed a legacy REST API that lacked updated authentication controls. The data included contact details, deal stages, and custom object fields but no payment information.
The company isolated the affected endpoints within four hours and notified impacted customers. Forensic analysis points to a compromised service account from a third-party integration partner. Salesforce has since enforced mandatory MFA on all legacy APIs.
This follows increased scrutiny of SaaS security after multiple 2025 incidents. Salesforce maintains SOC 2 and ISO 27001 certifications across its core platform. Customers can request detailed access logs through the Trust Center portal.
Why this matters
The breach highlights persistent risks in legacy API maintenance for large SaaS vendors. Enterprises must audit third-party integrations more rigorously to prevent similar exposures. Regulators may accelerate enforcement of stricter API security standards.
Industry impact includes higher demand for zero-trust architectures in CRM deployments. Vendors will likely increase spending on continuous API monitoring tools.