logo

Salesforce investigates customer data theft via Gainsight breach

ID: c829923a-3756-57a8-99ec-60c7b0b5001d

STIX ID: report--c829923a-3756-57a8-99ec-60c7b0b5001d

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-11-20

Date Updated: 2026-07-18

Author: Sergiu Gatlan

...
...

Salesforce revoked access and refresh tokens for Gainsight-published applications after detecting unusual activity that may have enabled unauthorized access to customer Salesforce data; Salesforce temporarily removed those apps from the AppExchange and notified affected customers. The incident is tied to stolen OAuth tokens and is presented as similar to an earlier Salesloft breach (attributed to extortion groups such as ShinyHunters/Scattered Lapsus$ Hunters) that exposed credentials and cloud access tokens across hundreds of organizations; ShinyHunters claim they accessed an additional 285 Salesforce instances via the Gainsight compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.