logo

Gainsight Cyber-Attack Affects More Salesforce Customers

ID: 66ff3f6c-2557-50c7-9bfa-662ac82c3250

STIX ID: report--66ff3f6c-2557-50c7-9bfa-662ac82c3250

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2025-11-26

Date Updated: 2026-04-22

...
...

Gainsight experienced a supply-chain-related security incident tied to a broader Salesforce compromise: Salesforce published IOCs showing initial unauthorized access on Nov 8 and roughly twenty suspicious intrusions between Nov 16–23 using VPNs and techniques like Salesforce-Multi-Org-Fetcher. Gainsight engaged Mandiant, rotated credentials, disabled Salesforce-connected functionality as a precaution, notified affected customers, and advised mitigation steps (rotate S3 keys, reset non-SSO passwords, reauthorize integrations) while some third-party connectors (HubSpot, Gong.io, Zendesk) were temporarily disabled.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.