Full Breakdown
Salesforce Investigates Data Breach Linked to Gainsight Applications
11/22/2025, 7:41:31 PM
Overview of the Incident
Salesforce is currently investigating a data breach involving Gainsight-published applications that may have exposed customer data. The company detected "unusual activity" linked to these applications, which are integrated into Salesforce environments. In response, Salesforce has temporarily revoked all access to Gainsight's applications and removed them from the AppExchange while the investigation continues. The breach is reportedly not due to any vulnerabilities within the Salesforce platform itself but rather through the external connections facilitated by the Gainsight applications.
Background and Context
This incident follows a series of similar breaches involving third-party integrations with Salesforce. Notably, a previous attack in August 2025, which targeted Salesloft Drift, compromised data from over 700 customers. Both breaches are believed to be linked to the same threat group, identified as ShinyHunters or UNC6240, which has exploited OAuth token vulnerabilities to gain unauthorized access to Salesforce data.
Key Figures and Groups
- Salesforce: A leading cloud-based CRM provider, serving over 150,000 businesses globally.
- Gainsight: A customer success platform that integrates with Salesforce and other CRMs, with approximately 1,000 customers.
- ShinyHunters (UNC6240): A cybercriminal group claiming responsibility for the Gainsight breach, asserting they had access to Gainsight for nearly three months prior to the incident.
Official Statements and Responses
Salesforce stated, "Our investigation indicates this activity may have enabled unauthorized access to certain customers’ Salesforce data through the app’s connection." They emphasized that the issue does not stem from a flaw in their platform but from the external connections of the Gainsight applications. Gainsight has confirmed its cooperation with Salesforce during the investigation and has engaged Google's Mandiant incident responders for assistance.
Criticism and Opposition
Experts have raised concerns about the systemic vulnerabilities associated with OAuth integrations. Austin Larsen, principal analyst at Google Threat Intelligence Group, noted that "adversaries are increasingly targeting the OAuth tokens of trusted third-party SaaS integrations." Critics argue that the reliance on user-approved app integrations without robust oversight leaves organizations vulnerable to such attacks.
Conflicting Reports and Gaps
While Salesforce has not disclosed the exact number of affected customers, Google Threat Intelligence Group is aware of over 200 potentially impacted Salesforce instances. The full scope of the breach and the specific organizations involved remain unclear, highlighting a gap in transparency regarding the incident's impact.
Verbatim Quotes
- “This is the new attack surface.” — Jaime Blasco, Co-founder of Nudge Security
- “We assess this is likely the same threat cluster — ShinyHunters or UNC6240 — related to other recent campaigns targeting Salesforce instances, such as UNC6040,” — Austin Larsen, Principal Analyst at GTIG
- “Gainsight was just a test to probe how much monitoring there is now,” — Anonymous ShinyHunters member
What's Next
Salesforce and Gainsight will continue their investigation into the breach, with updates expected as more information becomes available. Organizations using Gainsight applications are advised to review their third-party integrations and take precautionary measures to secure their data.
