Salesforce says customer data may be exposed in Gainsight incident – “unusual activity” being probed

  • Gainsight apps enabled unauthorized Salesforce data access, prompting token revocation and AppExchange removal
  • Incident linked to August 2025 Salesloft breach, where OAuth tokens exposed 1.5 billion records
  • ShinyHunters used stolen secrets to steal Gainsight customer contact and licensing data

The Salesloft Drift incident seems to have trickled downstream into Gainsight, resulting in hundreds more organizations potentially losing their sensitive data to hackers.

Salesforce has confirmed it saw “unusual activity” involving Gainsight-published applications connected to Salesforce.

Salesforce says that some of these apps “may have enabled unauthorized access to certain customers’ Salesforce data”, which forced it to revoke all active access and refresh token associated with Gainsight-published applications connected to Salesforce. Furthermore, it temporarily removed the apps from its AppExchange.

ShinyHunters claim responsibility

“There is no indication that this issue resulted from any vulnerability in the Salesforce platform,” the announcement reads. “The activity appears to be related to the app’s external connection to Salesforce. We have notified known affected customers directly and will continue to provide updates as appropriate.”

Gainsight is a company building a “customer success” platform through which businesses can manage and improve their post-sales relationships with customers (such as onboarding, adoption, retention, or renewal).

The company also builds different apps and integrations, some of which run natively inside Salesforce, while others connect through APIs.

At the same time, BleepingComputer claims the incident is actually a continuation of the August 2025 Salesloft breach.

This saw a group of criminals known as “Scattered Lapsus$ Hunters” stole OAuth tokens Salesloft used for its Drift AI chat integration with Salesforce, which gave them direct API access to customers’ Salesforce data.

Using the stolen tokens, they accessed around 760 Salesforce instances, and exfiltrated 1.5 billion records, including passwords, AWS keys, and Snowflake tokens.

Now, a member of that same group, ShinyHunters, told the publication they broke into Gainsight by using secrets stolen in the Salesloft incident.

Gainsight also confirmed that attack, and said the miscreants took business contact details such as names, business email addresses, phone numbers, regional/location details, licensing information, and support case contents.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

Apple is turning Siri into an AI bot that’s more like ChatGPT

Apple is planning a big Siri overhaul that will transform the voice assistant into an AI chatbot built directly into its iPhone and Mac,...

Anthropic’s new Claude ‘constitution’: be helpful and honest, and don’t destroy humanity

Anthropic is overhauling Claude's so-called "soul doc." The new missive is a 57-page document titled "Claude's Constitution," which details "Anthropic's intentions for the model's...

Apple is reportedly working on an AirTag-sized AI wearable

Apple is working on an AI-powered wearable pin with cameras and microphones designed to pick up a user's surroundings, according to a report from...

Everyone can hear your TV in their headphones using this transmitter

Sennheiser’s new Auracast transmitter can be purchased as part of a bundle with its new wireless headphones. | Image: Sennheiser As we've previously lamented, one...

Blue Origin’s Starlink rival TeraWave promises 6 terabit satellite internet

The Blue Origin New Glenn rocket lifts off at Launch Complex 36 in its second launch attempt at Cape Canaveral Space Force Station on...

Apple is reportedly developing a wearable AI pin

Apple will reportedly try to succeed where Humane failed (miserably). On Wednesday, The Information reported that the iPhone maker is working on an AI...

Apple is reportedly overhauling Siri to be an AI chatbot

Apple has been spinning its wheels for many months over its approach to artificial intelligence, but a strategy finally appears to be emerging for...

Marshall’s new Heddon hub adds multi-room audio to speakers with Auracast

Marshall plans to add seamless multi-room audio to its Bluetooth speakers via a newly announced music streaming hub called Heddon. The $300 hub makes...

A new LinkedIn phishing scam is targeting executives online – make sure you don’t fall for this

Sophisticated LinkedIn phishing uses fake job ads to target executives Attacks employ DLL sideloading and Python tools to install remote access trojansReliaQuest warns phishing...

Report: Apple does about-face on Siri chatbot — and it might compete directly with ChatGPT and Google

Apple promised us this was never the plan...until we guess, it became the plan: A new report from Apple soothsayer Mark Gurman says Apple...