Salesforce has detected unusual activity involving Gainsight-published applications connected to its platform, resulting in potential unauthorized access to certain customers' Salesforce data. The company responded by revoking all active access and refresh tokens associated with these applications and temporarily removing them from the AppExchange while the investigation is ongoing. Salesforce emphasized that the incident did not stem from a vulnerability in its core CRM platform, but rather from the external connection established by the Gainsight applications, which are managed directly by customers.
Impacted customers have been notified, and Salesforce has advised those needing further assistance to contact their support team. This breach follows a similar pattern to the August 2025 Salesloft incident, where attackers exploited OAuth tokens to access sensitive customer data. While the full scope of the current Gainsight-related breach is still under investigation, the incident highlights the risks associated with third-party integrations and the importance of monitoring external application connections to critical cloud services.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
14 events from the most recent confirmed update back to the earliest known activity.
By November 27, 2025, Gainsight disclosed that more customers were affected than initially reported. The update marked an escalation from earlier statements that had minimized the number of impacted organizations.
On November 26, 2025, Gainsight CEO Chuck Ganapathi said only a handful of customers had data stolen, contrasting with outside estimates that more than 200 Salesforce instances may have been affected. The statement highlighted ongoing uncertainty over the breach's true scale.
On November 26, 2025, reporting on Salesforce's latest guidance said only a handful of customers were confirmed to have had data impacted so far, despite broader claims from the threat actor and outside researchers. The company continued to investigate the full scope of exposure.
By November 24, 2025, Salesforce and security reporting described the incident as a supply-chain attack carried out through Gainsight OAuth access to customer Salesforce instances. Mandiant was publicly identified as assisting with forensic investigation and hardening recommendations.
Around November 24-26, 2025, Salesforce and Gainsight released customer guidance and indicators of compromise, including suspicious IP addresses and user-agent details. Customers were advised to review logs, revoke and reauthorize tokens, and rotate potentially exposed credentials.
On November 23, 2025, Gainsight confirmed it was actively investigating suspicious activity involving its Salesforce-integrated applications. The company worked with Salesforce and Mandiant as the scope and customer impact were assessed.
During the response, Gainsight also pulled its app from the HubSpot Marketplace and revoked connector access for services such as Zendesk, with some reports also mentioning Gong.io. These steps were taken to limit further abuse of connected SaaS integrations.
By November 20, 2025, multiple reports attributed the campaign to ShinyHunters, also described in some coverage as overlapping with UNC6395 or Scattered Lapsus$ Hunters. The group claimed responsibility and tied the activity to earlier third-party Salesforce ecosystem compromises.
On November 20, 2025, Gainsight reported connection failures affecting its Salesforce connector. The disruption aligned with Salesforce's containment actions and signaled that the vendor was actively responding to the incident.
Salesforce published a security advisory about unusual activity related to Gainsight applications and warned customers to review connected apps and credentials. The advisory formalized the incident publicly after direct customer notifications had begun.
As a containment step on November 19, 2025, Salesforce revoked all active access and refresh tokens associated with Gainsight applications and temporarily removed those apps from AppExchange. This cut off affected third-party integrations while the investigation proceeded.
On November 19, 2025, Salesforce detected unusual activity and suspicious API calls involving Gainsight-published applications connected to customer Salesforce environments. The company said affected customers were being notified and that there was no evidence of a vulnerability in the core Salesforce platform.
Salesforce later traced additional malicious activity between November 16 and November 23 to commercial VPNs, Tor exit nodes, and AWS infrastructure. The infrastructure and tradecraft were linked by multiple reports to ShinyHunters or related clusters.
Salesforce later said indicators of compromise showed unauthorized access tied to Gainsight-published applications began as early as November 8, 2025. The activity involved abuse of OAuth-connected third-party integrations rather than a flaw in Salesforce itself.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
33 references tracked. Mallory keeps watching after this page renders.
secpod.com
Open sourcethehackernews.com
Open sourcego.theregister.com
Open sourcehelpnetsecurity.com
Open sourcehelpnetsecurity.com
Open sourcesecurityboulevard.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.