Scattered Lapsus$ Shiny Hunters Strikes Salesforce Again
ID: 8eb61f94-b83d-5ab6-8658-d8de356d74b7
STIX ID: report--8eb61f94-b83d-5ab6-8658-d8de356d74b7
Feed Name: Mitiga
This report details a multi-month supply-chain compromise of Gainsight (Aug–Nov 2025) that resulted in OAuth refresh tokens being issued for up to ~285 Salesforce instances; attackers (claimed by SLSH/ShinyHunters) used automated API access (noted IP 3.239.45.43 and Python/aiohttp user-agent) and Salesforce revoked access after anomalous activity was detected. The intrusion enabled potential full exfiltration and manipulation of sensitive Salesforce and Gainsight data, possible execution of Apex via Gainsight permission sets, and broad API-enabled data extraction; Mitiga provides detections, IOCs, and remediation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
