Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

CMC Releases Analysis and Guidance for Education Sector After Canvas D

June 26, 2026

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

June 26, 2026

macOS Flaw Lets Standard Users Disable EDR and MDM

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»New Gainsight Supply Chain Hack Could Affect Salesforce Customers
News

New Gainsight Supply Chain Hack Could Affect Salesforce Customers

Team-CWDBy Team-CWDNovember 21, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A new cyber incident could have affected Salesforce customer data three months after the Salesloft Drift hack.

On November 20, customer support platform provider Gainsight said it identified connection failures resulting from Salesforce revoking active access for Gainsight SFDC Connector, which allows Gainsight applications to connect to Salesforce.

In a Salesforce security advisory, also published on November 20, the firm noted it had identified unusual activity involving Gainsight-published applications connected to Salesforce.

This prompted the company to revoke access to all Gainsight applications and temporarily removed them from its AppExchange.

Salesforce assessed that malicious activity may have enabled unauthorized access to its customers’ data through the app’s connection.

“There is no indication that this issue resulted from any vulnerability in the Salesforce platform. The activity appears to be related to the app’s external connection to Salesforce,” the Salesforce advisory reads.

Gainsight also disabled its connections with Hubspot and Zendesk as a precaution measure.

In a later update, the customer support provider said it has engaged Google Cloud-owned Mandiant to assist in the forensic investigation.

Scattered Lapsus$ Hunters Claim the Gainsight Hack

In the blog DataBreaches.net, the author known as ‘Dissent’ said they asked individuals behind the Scattered Spider-ShinyHunters-Lapsus$ collective (sometimes referred to as ‘Scattered Lapsus$ Hunters’), who confirmed they were responsible for the attack targeting Gainsight.

The threat actors also told Dissent they plan to launch another dedicated leak site if Salesforce does not comply with them.

This data leak site (DLS) will contain the data of the Salesloft and Gainsight campaigns. In total this is almost 1000 companies according to the cybercriminal’s claims.

“Only actual companies, mainly Fortune 500 will be listed or things I feel would be worth it. From the Gainsight campaign the large companies were: Verizon, Gitlab, F5, Sonicwall, and others,” the treat actor told DataBreaches.net.

Finally, the group advertised an upcoming ransomware as-a-service (RaaS) offering, allegedly launching on November 24.

Ferhat Dikbiyik, chief research and intelligence Officer (CRIO) at Black Kite, commented: “Gainsight has already acknowledged exposure in a previous campaign involving Salesloft Drift, where stolen OAuth tokens were used to access Salesforce data across many organizations. In that earlier case, Gainsight disconnected the Salesloft app and confirmed that only customer relationship management-layer (CRM) data, mostly business contact info and some Salesforce case text, had been accessed.”

“Fast-forward to today, and we’re seeing the same playbook again: OAuth tokens + over-permissioned apps + integrated vendors = a perfect attack chain. This isn’t about one vendor or one platform. This is about how modern software-as-a-service (SaaS) ecosystems operate: wide, connected, and often over-trusted,” he added.

Infosecurity contacted Gainsight for comment but did not receive a response by the time of publication.

Photo credits: Jonathan Weiss / gguy / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMicrosoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack
Next Article Amazon Uncovers Attacks Exploited Cisco ISE and Citrix NetScaler as Zero-Day Flaws
Team-CWD
  • Website

Related Posts

News

CMC Releases Analysis and Guidance for Education Sector After Canvas D

June 26, 2026
News

DragonForce Hackers Abuse Microsoft Teams Relays to Hide Backdoor.Turn C2 Traffic

June 26, 2026
News

macOS Flaw Lets Standard Users Disable EDR and MDM

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

It’s all fun and games until someone gets hacked

September 26, 2025

Is it OK to let your children post selfies online?

February 17, 2026

Managing risks to your loved one’s digital estate

April 2, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.