logo

Deja Vu: Salesforce Customers Hacked Again, Via Gainsight

ID: 7272468b-d8ed-540d-944d-86c0a08f6280

STIX ID: report--7272468b-d8ed-540d-944d-86c0a08f6280

Feed Name: Dark Reading

Threat Score
78/100

Date Published: 2025-11-21

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Hackers linked to ShinyHunters executed supply-chain breaches of Salesforce-connected third-party apps (Drift earlier, then Gainsight), stole OAuth tokens, and used them to access hundreds — reportedly up to ~1,000 — customer Salesforce instances and associated business data; Salesforce responded by revoking tokens and temporarily removing affected apps while urging customers to review logs and enforce least-privilege app permissions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.