Gainsight CEO downplays impact of attack that spread to Salesforce environments
ID: e5209478-7fe9-59f3-b744-378591e22f5d
STIX ID: report--e5209478-7fe9-59f3-b744-378591e22f5d
Feed Name: CyberScoop
Gainsight's Salesforce connected app was involved in a supply-chain breach that resulted in compromised OAuth tokens; Salesforce, Gainsight and Mandiant are investigating and Salesforce has published IOCs and activity dates while Google TAG reported more than 200 potentially affected Salesforce instances though only a handful of customers are known to have confirmed data impact. Gainsight recommends focusing investigations on Salesforce-side logs and applying IP restrictions; the incident is being analyzed for extent of token abuse and downstream compromise and is compared to prior Salesloft/Drift downstream attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
