August 28, 2025
At Lucid, protecting your data and maintaining transparency are core to our business, and as such, we are committed to keeping you informed about developments that may impact your organization. Lucid was made aware of a campaign targeted at the Salesloft Drift application, which impacted a large number of Salesforce customers, including us.
This incident was not a breach of Lucid Software's SaaS (lucid.app). No Lucid production data was accessed or impacted (software code, products, the data secured by those products, or our internal network).
Once we learned of the incident, we immediately removed the Drift application from all connected internal applications, launched an internal investigation, and engaged third-party cybersecurity experts to validate the results of our investigation.
As a result of our response, we believe only a small fraction of Lucid users were impacted, and the only information accessed for impacted individuals is limited to:
- name and e-mail address,
- if collected, phone number, company name, job title, and billing address, and
- initial ticket information from a limited number of support requests, including similar personal data as listed above.
Although the incident’s scope remains limited, we recommend that customers maintain heightened vigilance of their internal security safeguards, including awareness of potential phishing attacks or social engineering attempts.
We understand the importance of your data security and will continue to monitor this situation closely. We’ll provide updates and implement additional proactive measures as necessary.
