We recently learned of a security incident involving Salesforce and Salesloft Drift, two systems we use for customer relationship management. Specifically, the Salesforce/Drift integration – which is used by hundreds of companies, including eMoney – was the target of a malicious actor, and our customer records may have been accessed through a vendor’s compromised credentials.
Once notified, eMoney immediately took steps to contain the incident. The affected systems are not used to store end-client/consumer personally identifiable information (PII) and, therefore, we expect that any legally required notice obligations will be minimal.
As part of our security precautions, the Salesforce/Drift integration, along with our website chat bot that is powered by Drift, have been disabled.
Additionally, our ongoing investigation shows that there may have been exposure of eMoney names, email addresses, and job titles.
We ask that you continue to be vigilant of any phishing or social engineering attacks. If you suspect you are the target of a phishing or social engineering attack, promptly use the “Report Phishing” button on the email or contact Security@emoneyadvisor.com.
We’ve begun communicating this incident to enterprise home offices. If you receive any client inquiries about this incident, please route them to Customer Security Inquiries at csi@emoneyadvisor.com.
Leave a Reply