logo

Gainsight CEO downplays impact of attack that spread to Salesforce environments

ID: e5209478-7fe9-59f3-b744-378591e22f5d

STIX ID: report--e5209478-7fe9-59f3-b744-378591e22f5d

Feed Name: CyberScoop

Threat Score
70/100

Date Published: 2025-11-25

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Gainsight's Salesforce connected app was involved in a supply-chain breach that resulted in compromised OAuth tokens; Salesforce, Gainsight and Mandiant are investigating and Salesforce has published IOCs and activity dates while Google TAG reported more than 200 potentially affected Salesforce instances though only a handful of customers are known to have confirmed data impact. Gainsight recommends focusing investigations on Salesforce-side logs and applying IP restrictions; the incident is being analyzed for extent of token abuse and downstream compromise and is compared to prior Salesloft/Drift downstream attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.