Deja Vu: Salesforce Customers Hacked Again, Via Gainsight
ID: 7272468b-d8ed-540d-944d-86c0a08f6280
STIX ID: report--7272468b-d8ed-540d-944d-86c0a08f6280
Feed Name: Dark Reading
Threat Score
Hackers linked to ShinyHunters executed supply-chain breaches of Salesforce-connected third-party apps (Drift earlier, then Gainsight), stole OAuth tokens, and used them to access hundreds — reportedly up to ~1,000 — customer Salesforce instances and associated business data; Salesforce responded by revoking tokens and temporarily removing affected apps while urging customers to review logs and enforce least-privilege app permissions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
