logo

The Salesforce-Gainsight Security Incident: What You Need to Know

ID: 0b2b5edd-de48-5f62-a67e-e2afc8ea1958

STIX ID: report--0b2b5edd-de48-5f62-a67e-e2afc8ea1958

Feed Name: Recorded Future Blog

Threat Score
70/100

Date Published: 2025-11-26

Date Updated: 2026-04-28

...
...

On November 19–23, 2025, Salesforce and Gainsight investigated suspicious API activity originating from non-allowlisted IP addresses via Gainsight’s Salesforce integrations; Salesforce revoked related access tokens, restricted integration functionality, and several services and third-party connectors were temporarily disabled. Indicators point to Tor/proxy infrastructure and IPs previously tied to an August 2025 UNC6040 CRM campaign, with malware families (SmokeLoader, Stealc, DCRat, Vidar) observed communicating with implicated IPs; Gainsight reports no confirmed exfiltration so far and has taken mitigation steps while recommending token rotation, log review, allowlisting, MFA enforcement, and isolation/reauthorization of integrations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.