Google security experts say Gainsight attacks may have left hundreds of companies affected



  • Google Threat Intelligence Group says Gainsight breach may have affected more than 200 Salesforce instances
  • The attack stems from the August 2025 Salesloft breach, where scattered Lapsus$ hunters stole and abused OAuth tokens.
  • SHL claims victims include Atlassian, CrowdStrike, LinkedIn and others, although none have confirmed the compromise

Security experts at Google believe that the recent Gainsight breach may have left more than 200 companies and the data they stored through Salesforce compromised.

Salesforce recently confirmed seeing “unusual activity” involving apps published by Gainsight connected to its systems. At the time, it said that some of the apps may have allowed unauthorized access to certain customers’ Salesforce data,” forcing it to revoke all active access and refresh tokens associated with Gainsight-published apps connected to Salesforce, and to temporarily remove the apps from its AppExchange.



Leave a Comment

Your email address will not be published. Required fields are marked *