Google security experts say Gainsight hacks may have left hundreds of companies affected



  • Google Threat Intelligence Group says the Gainsight breach may have impacted 200+ Salesforce instances
  • Attack stems from the August 2025 Salesloft breach, where OAuth tokens were stolen and abused by Scattered Lapsus$ Hunters
  • SHL claims victims include Atlassian, CrowdStrike, LinkedIn, and others, though none have confirmed compromise

Google’s security experts believe the recent Gainsight breach may have left more than 200 companies, and the data they stored through Salesforce, compromised.

Salesforce recently confirmed seeing “unusual activity” involving Gainsight-published applications connected to its systems. At the time, it said some of the apps may have enabled unauthorized access to certain customers’ Salesforce data”, which forced it to revoke all active access and refresh token associated with Gainsight-published applications connected to Salesforce, and to temporarily remove the apps from its AppExchange.


https://cdn.mos.cms.futurecdn.net/pVCXKrhThqmUjYVSZBjV5Z-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img