HackingVulnerability ExploitCapture Stored DataZero-DaySupply Chain (3P Vendor)Downstream VictimsCustomer Data InvolvedData ExfiltratedPIIPHILowContained
PHREESIA, INC.
bd_26337698165afc92 · schema v1 · pii pii-v1
Full breach record for PHREESIA, INC. →Phreesia, Inc., a healthcare patient check-in technology company, was impacted by a zero-day vulnerability in third-party software Salesloft Drift, which allowed an unknown threat actor to access Salesforce environments of hundreds of organizations on August 17, 2025. Service tickets containing limited patient information were exposed. 18 Rhode Island residents were identified as affected. Phreesia stopped use of the tool, engaged external cybersecurity experts, and offered two-year Kroll identity monitoring to affected individuals.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed18 affectedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-618283
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Aug 17, 2025
- Raw hash
- b0ec72aa63f2b20122c0d61f80ad404543c88d1d44fd332f510be9151d04c23a
Reporting entity
- Name
- PHREESIA, INC.norm: phreesia
- Domain
- phreesia.com
Victim entity
- Name
- PHREESIA, INC.norm: phreesia
- Domain
- phreesia.com
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 18
- Data types
- PIIPHI
- Attack vector
- Third-Party / Supply Chain
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1195 Supply Chain CompromiseT1530 Data from Cloud Storage Object
- Threat actor
- External
- Third party
- via Salesloft Drift
- Initial access
- exploit_public_facing
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.