{"id":8624,"date":"2025-11-21T10:03:39","date_gmt":"2025-11-21T10:03:39","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/21\/salesforce-confirms-that-customers-data-was-accessed-following-the-gainsight-breach\/"},"modified":"2025-11-21T10:03:39","modified_gmt":"2025-11-21T10:03:39","slug":"salesforce-confirms-that-customers-data-was-accessed-following-the-gainsight-breach","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/21\/salesforce-confirms-that-customers-data-was-accessed-following-the-gainsight-breach\/","title":{"rendered":"Salesforce Confirms that Customers\u2019 Data Was Accessed Following the Gainsight Breach"},"content":{"rendered":"<p>    Salesforce Confirms that Customers\u2019 Data Was Accessed Following the Gainsight Breach<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Salesforce has issued a critical security alert identifying \u201cunusual activity\u201d involving Gainsight-published applications connected to customer environments.<\/p>\n<p>The CRM giant\u2019s investigation indicates that this activity may have enabled unauthorized access to Salesforce data through the applications\u2019 external connections.<\/p>\n<p>In an immediate response to contain the threat, Salesforce has revoked all active access and refresh tokens associated with the affected Gainsight apps and temporarily removed them from the AppExchange.\u200b<\/p>\n<p>Salesforce explicitly <a href=\"https:\/\/status.salesforce.com\/generalmessages\/20000233\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">stated<\/a> that this incident does not stem from a vulnerability within the Salesforce platform itself. Instead, it exploits the trust relationship between the platform and third-party integrations.<\/p>\n<p>The attack leverages compromised OAuth tokens and digital keys that allow apps to access data without sharing user credentials.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-salesforce-gainsight-breach\"><strong>Salesforce Gainsight Breach<\/strong><\/h2>\n<p>This mirrors the tactics used in the <a href=\"https:\/\/cybersecuritynews.com\/salesloft-drift-data-breaches\/\" target=\"_blank\" rel=\"noreferrer noopener\">August 2025 campaign<\/a> involving Salesloft Drift, in which attackers used stolen OAuth tokens to bypass authentication and access CRM-layer data, such as business contacts and case logs, across hundreds of organizations.\u200b<\/p>\n<p>Gainsight had previously acknowledged its exposure to the Salesloft Drift incident, confirming that stolen secrets from that breach were the likely root cause. Now, threat actors appear to be replaying the same playbook: combining stolen OAuth tokens with over-permissioned applications to create a \u201cperfect attack chain\u201d that bypasses traditional perimeter defenses.\u200b<\/p>\n<p>Security researchers have linked this campaign to <a href=\"https:\/\/cybersecuritynews.com\/shinyhunters-possibly-collaborates-with-scattered-spider\/\">ShinyHunters<\/a> (also tracked as UNC6040), a threat group notorious for targeting SaaS ecosystems. This group typically employs social engineering to trick users into approving malicious apps or, as seen here, pivots from one compromised vendor to another.<\/p>\n<p>From a Third-Party Risk Management (TPRM) perspective, this incident exemplifies a \u201csupply-chain blast radius\u201d event, where a single compromised vendor serves as a gateway into dozens of downstream environments.<\/p>\n<p>Risk in modern SaaS ecosystems no longer travels linearly; it fans out, creating exponential exposure from a single point of failure.\u200b<\/p>\n<p>Organizations using Gainsight integrations must assume their current connections are compromised until re-authenticated. Teams should immediately audit every connected app in their Salesforce instance, removing or restricting any integration that does not require wide API access.<\/p>\n<p>It is critical to rotate vendor <a href=\"https:\/\/cybersecuritynews.com\/salesloft-drift-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">OAuth tokens<\/a> immediately and treat any token with broad permissions as high-risk. Furthermore, security teams should harden their approval processes for new integrations, as threat actors have previously used <a href=\"https:\/\/cybersecuritynews.com\/social-engineering\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering<\/a> to get malicious apps approved. <\/p>\n<p>Ferhat Dikbiyik, Chief Research and Intelligence Officer (CRIO) at Black Kite, said to cybersecuritynews.com \u201cthat this wasn\u2019t a breach of Salesforce\u2019s core platform. Instead, attackers linked to ShinyHunters (ScatteredSpider Lapsu$ Hunters) exploited a third-party integration, using access from a compromised vendor to pull customer data out of Salesforce environments. And there\u2019s an important pattern here\u201d.<\/p>\n<p>\u201cGainsight has already acknowledged exposure in a previous campaign involving Salesloft Drift, where stolen OAuth tokens were used to access Salesforce data across many organizations. In that earlier case, Gainsight disconnected the Salesloft app and confirmed that only CRM-layer data, mostly business contact info and some Salesforce case text, had been accessed\u201d.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/salesforce-gainsight-breach\/\">Salesforce Confirms that Customers\u2019 Data Was Accessed Following the Gainsight Breach<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Guru Baran<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/salesforce-gainsight-breach\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Salesforce Confirms that Customers\u2019 Data Was Accessed Following the Gainsight Breach Salesforce has issued a critical security alert identifying \u201cunusual activity\u201d involving Gainsight-published applications connected to customer environments. The CRM giant\u2019s investigation indicates that this activity may have enabled unauthorized access to Salesforce data through the applications\u2019 external connections. In an immediate response to contain [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,156],"tags":[130],"class_list":["post-8624","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-data-breach","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8624"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8624"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8624\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8624"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8624"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8624"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}