Technology

Salesforce says customer data may be exposed in Gainsight incident - "unusual activity" being probed

2025-11-21 14:29
663 views
Salesforce says customer data may be exposed in Gainsight incident - "unusual activity" being probed

New attacks show the effects of the Salesloft breach are still being felt.

  1. Pro
  2. Security
Salesforce says customer data may be exposed in Gainsight incident - "unusual activity" being probed News By Sead Fadilpašić published 21 November 2025

Effects of the Salesloft breach are still being felt

Comments (0) ()

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works.

Hands on a laptop with overlaid logos representing network security (Image credit: Thapana Onphalai via Getty Images)
  • Gainsight apps enabled unauthorized Salesforce data access, prompting token revocation and AppExchange removal
  • Incident linked to August 2025 Salesloft breach, where OAuth tokens exposed 1.5 billion records
  • ShinyHunters used stolen secrets to steal Gainsight customer contact and licensing data

The Salesloft Drift incident seems to have trickled downstream into Gainsight, resulting in hundreds more organizations potentially losing their sensitive data to hackers.

Salesforce has confirmed it saw “unusual activity” involving Gainsight-published applications connected to Salesforce.

  • Amazon Black Friday deals are live: here are our picks!

Salesforce says that some of these apps “may have enabled unauthorized access to certain customers’ Salesforce data”, which forced it to revoke all active access and refresh token associated with Gainsight-published applications connected to Salesforce. Furthermore, it temporarily removed the apps from its AppExchange.

You may like
  • Protection from AI hacker attacks Google warns Salesloft Drift attack may have compromised Workspace accounts and Salesforce instances
  • Agentforce World Tour London Hackers claim they stole 1.5 billion Salesforce records from hundreds of companies in major hack - but are they telling the truth?
  • Code Skull Hackers claim to have stolen over a billion Salesforce records - and are demanding nearly $1 billion not to leak them

ShinyHunters claim responsibility

“There is no indication that this issue resulted from any vulnerability in the Salesforce platform,” the announcement reads. “The activity appears to be related to the app’s external connection to Salesforce. We have notified known affected customers directly and will continue to provide updates as appropriate.”

Gainsight is a company building a “customer success” platform through which businesses can manage and improve their post-sales relationships with customers (such as onboarding, adoption, retention, or renewal).

The company also builds different apps and integrations, some of which run natively inside Salesforce, while others connect through APIs.

At the same time, BleepingComputer claims the incident is actually a continuation of the August 2025 Salesloft breach.

Are you a pro? Subscribe to our newsletterContact me with news and offers from other Future brandsReceive email from us on behalf of our trusted partners or sponsorsBy submitting your information you agree to the Terms & Conditions and Privacy Policy and are aged 16 or over.

This saw a group of criminals known as "Scattered Lapsus$ Hunters" stole OAuth tokens Salesloft used for its Drift AI chat integration with Salesforce, which gave them direct API access to customers’ Salesforce data.

Using the stolen tokens, they accessed around 760 Salesforce instances, and exfiltrated 1.5 billion records, including passwords, AWS keys, and Snowflake tokens.

Now, a member of that same group, ShinyHunters, told the publication they broke into Gainsight by using secrets stolen in the Salesloft incident.

Gainsight also confirmed that attack, and said the miscreants took business contact details such as names, business email addresses, phone numbers, regional/location details, licensing information, and support case contents.

Best antivirus software headerThe best antivirus for all budgetsOur top picks, based on real-world testing and comparisons

➡️ Read our full guide to the best antivirus1. Best overall:Bitdefender Total Security2. Best for families:Norton 360 with LifeLock3. Best for mobile:McAfee Mobile Security

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

TOPICS Salesforce Sead FadilpašićSocial Links Navigation

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

You must confirm your public display name before commenting

Please logout and then login again, you will then be prompted to enter your display name.

Logout Read more Protection from AI hacker attacks Google warns Salesloft Drift attack may have compromised Workspace accounts and Salesforce instances    Agentforce World Tour London Hackers claim they stole 1.5 billion Salesforce records from hundreds of companies in major hack - but are they telling the truth?    Code Skull Hackers claim to have stolen over a billion Salesforce records - and are demanding nearly $1 billion not to leak them    Representational image depecting cybersecurity protection Palo Alto Networks becomes the latest to confirm it was hit by Salesloft Drift attack    IA y ciberseguridad Zscaler says it suffered data breach following Salesloft Drift compromise    Person in suit with grid of data and tablet Even Cloudflare isn't safe from Salesloft Drift data breaches    Latest in Security AI Agent AI agents are fuelling an identity and security crisis for organizations    Phishing, E-Mail, Network Security, Computer Hacker, Cloud Computing Cyber Security 3d Illustration Gaming and gambling giant IGT reportedly hit by ransomware - here's what we know    Robotic mask face with electronic wires in a sci-fi technology or artificial intelligence network concept. China’s PlushDaemon group uses EdgeStepper implant to infect network devices with SlowStepper malware in global supply-chain attacks    Abstract image of cyber security in action. Perplexity's Comet AI browser may have some concerning security flaws which could let hacker hijack your device    WordPress logo on mobile WordPress plugin with over a million installs may have a worrying security flaw - here's what we know    Best free Linux firewalls Fortinet admits it found another worrying zero-day being exploited in attacks    Latest in News The Fitbit Charge 4 and the Fitbit app Fitbit's new AI tool wants to take the stress out of your next doctor's visit    PERTH, AUSTRALIA - NOVEMBER 21: England captain Ben Stokes celebrates with Brydon Carse after dismissing Travis Head of Australia during day one of the First 2025/26 Ashes Series Test Match between Australia and England at Perth Stadium on November 21, 2025 in Perth, Australia. How to watch The Ashes 2025-26 highlights on BBC iPlayer — it's *FREE*    Lenovo Legion Go 2 'Full Screen Experience' is now coming to all Windows 11 handhelds    AirDrop on an Apple device. Apple might not block Google's clever new AirDrop trick for 3 key reasons    Cloud in Hand Global cloud wars see AWS increasingly under threat from Microsoft and Google    Stress Upgrading tech could help UK businesses offset time lost on sick leave    LATEST ARTICLES