Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Salesforce Confirms that Customers’ Data Was accessed Following the Gainsight Breach

Salesforce Confirms that Customers’ Data Was accessed Following the Gainsight Breach

Posted on November 21, 2025November 21, 2025 By CWS

Salesforce has issued a essential safety alert figuring out “uncommon exercise” involving Gainsight-published functions related to buyer environments.

The CRM large’s investigation signifies that this exercise might have enabled unauthorized entry to Salesforce knowledge by means of the functions’ exterior connections.

In a right away response to include the risk, Salesforce has revoked all lively entry and refresh tokens related to the affected Gainsight apps and briefly eliminated them from the AppExchange.​

Salesforce explicitly acknowledged that this incident doesn’t stem from a vulnerability inside the Salesforce platform itself. As an alternative, it exploits the belief relationship between the platform and third-party integrations.

The assault leverages compromised OAuth tokens and digital keys that permit apps to entry knowledge with out sharing consumer credentials.

Salesforce Gainsight Breach

This mirrors the ways used within the August 2025 marketing campaign involving Salesloft Drift, wherein attackers used stolen OAuth tokens to bypass authentication and entry CRM-layer knowledge, corresponding to enterprise contacts and case logs, throughout a whole lot of organizations.​

Gainsight had beforehand acknowledged its publicity to the Salesloft Drift incident, confirming that stolen secrets and techniques from that breach have been the doubtless root trigger. Now, risk actors seem like replaying the identical playbook: combining stolen OAuth tokens with over-permissioned functions to create a “good assault chain” that bypasses conventional perimeter defenses.​

Safety researchers have linked this marketing campaign to ShinyHunters (additionally tracked as UNC6040), a risk group infamous for concentrating on SaaS ecosystems. This group sometimes employs social engineering to trick customers into approving malicious apps or, as seen right here, pivots from one compromised vendor to a different.

From a Third-Get together Threat Administration (TPRM) perspective, this incident exemplifies a “supply-chain blast radius” occasion, the place a single compromised vendor serves as a gateway into dozens of downstream environments.

Threat in fashionable SaaS ecosystems now not travels linearly; it followers out, creating exponential publicity from a single level of failure.​

Organizations utilizing Gainsight integrations should assume their present connections are compromised till re-authenticated. Groups ought to instantly audit each related app of their Salesforce occasion, eradicating or limiting any integration that doesn’t require broad API entry.

It’s essential to rotate vendor OAuth tokens instantly and deal with any token with broad permissions as high-risk. Moreover, safety groups ought to harden their approval processes for brand new integrations, as risk actors have beforehand used social engineering to get malicious apps authorised.

Ferhat Dikbiyik, Chief Analysis and Intelligence Officer (CRIO) at Black Kite, mentioned to cybersecuritynews.com “that this wasn’t a breach of Salesforce’s core platform. As an alternative, attackers linked to ShinyHunters (ScatteredSpider Lapsu$ Hunters) exploited a third-party integration, utilizing entry from a compromised vendor to drag buyer knowledge out of Salesforce environments. And there’s an necessary sample right here”.

“Gainsight has already acknowledged publicity in a earlier marketing campaign involving Salesloft Drift, the place stolen OAuth tokens have been used to entry Salesforce knowledge throughout many organizations. In that earlier case, Gainsight disconnected the Salesloft app and confirmed that solely CRM-layer knowledge, largely enterprise contact information and a few Salesforce case textual content, had been accessed”.

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Accessed, Breach, Confirms, Customers, Data, Gainsight, Salesforce

Post navigation

Previous Post: Oracle Allegedly Breached by Clop Ransomware via E-Business Suite 0-Day Hack
Next Post: Salesforce Flags Unauthorized Data Access via Gainsight-Linked OAuth Activity

Related Posts

Federal IT contractor Agrees to Pay .75M Over False Cybersecurity Services Claim Federal IT contractor Agrees to Pay $14.75M Over False Cybersecurity Services Claim Cyber Security News
Checkpoint Details on How Attackers Drained 8M from Balancer Pools Within 30 Minutes Checkpoint Details on How Attackers Drained $128M from Balancer Pools Within 30 Minutes Cyber Security News
Russian Vodka Producer Beluga Hit by Ransomware Attack Russian Vodka Producer Beluga Hit by Ransomware Attack Cyber Security News
Tenda N300 Vulnerabilities Let Attacker to Execute Arbitrary Commands as Root User Tenda N300 Vulnerabilities Let Attacker to Execute Arbitrary Commands as Root User Cyber Security News
Microsoft Teams New feature Allows Users to Flag Malicious Calls Microsoft Teams New feature Allows Users to Flag Malicious Calls Cyber Security News
Hackers Using Calendly-Themed Phishing Attack to Steal Google Workspace Account Hackers Using Calendly-Themed Phishing Attack to Steal Google Workspace Account Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Muddled Libra Exploits VMware vSphere in Cyber Attack
  • Feiniu NAS Devices Targeted in Major Botnet Attack
  • Rapid SSH Worm Exploits Linux Systems with Credential Stuffing
  • Odido Telecom Hacked: 6.2 Million Accounts Compromised
  • Lazarus Group Targets npm and PyPI with Malicious Packages

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News