Gainsight Cyber-Attack Affects More Salesforce Customers
ID: 66ff3f6c-2557-50c7-9bfa-662ac82c3250
STIX ID: report--66ff3f6c-2557-50c7-9bfa-662ac82c3250
Feed Name: Infosecurity Magazine (News)
Gainsight experienced a supply-chain-related security incident tied to a broader Salesforce compromise: Salesforce published IOCs showing initial unauthorized access on Nov 8 and roughly twenty suspicious intrusions between Nov 16–23 using VPNs and techniques like Salesforce-Multi-Org-Fetcher. Gainsight engaged Mandiant, rotated credentials, disabled Salesforce-connected functionality as a precaution, notified affected customers, and advised mitigation steps (rotate S3 keys, reset non-SSO passwords, reauthorize integrations) while some third-party connectors (HubSpot, Gong.io, Zendesk) were temporarily disabled.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
