logo

Scattered Lapsus$ Shiny Hunters Strikes Salesforce Again

ID: 8eb61f94-b83d-5ab6-8658-d8de356d74b7

STIX ID: report--8eb61f94-b83d-5ab6-8658-d8de356d74b7

Feed Name: Mitiga

Threat Score
85/100

Date Published: 2026-07-16

Date Updated: 2026-07-29

...
...

This report details a multi-month supply-chain compromise of Gainsight (Aug–Nov 2025) that resulted in OAuth refresh tokens being issued for up to ~285 Salesforce instances; attackers (claimed by SLSH/ShinyHunters) used automated API access (noted IP 3.239.45.43 and Python/aiohttp user-agent) and Salesforce revoked access after anomalous activity was detected. The intrusion enabled potential full exfiltration and manipulation of sensitive Salesforce and Gainsight data, possible execution of Apex via Gainsight permission sets, and broad API-enabled data extraction; Mitiga provides detections, IOCs, and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.