Salesforce Says Customer Data May Be Exposed in Gainsight Incident - "Unusual Activity" Being Probed

Salesforce Says Customer Data May Be Exposed in Gainsight Incident - "Unusual Activity" Being Probed

TechRadar
TechRadarNov 21, 2025

Companies Mentioned

Why It Matters

The incident highlights the systemic risk posed by third‑party integrations and compromised OAuth tokens, underscoring the need for tighter security controls across SaaS ecosystems and potentially prompting stricter vetting of AppExchange partners.

Summary

Salesforce disclosed that unauthorized access to customer data occurred through Gainsight‑published applications on its platform, prompting the company to revoke all active access and refresh tokens for those apps and temporarily pull them from the AppExchange. The breach is linked to the ShinyHunters group, which leveraged OAuth tokens stolen in the August 2025 Salesloft breach to infiltrate Gainsight’s external connections, extracting business contact details, licensing information, and support case content. Salesforce emphasized that the incident did not stem from a vulnerability in its core platform but from the third‑party app’s external integration. Affected customers have been notified directly and further updates will be provided.

Salesforce says customer data may be exposed in Gainsight incident - "unusual activity" being probed

Comments

Want to join the conversation?

Loading comments...