Salesforce Says Customer Data May Be Exposed in Gainsight Incident: ‘Unusual Activity’ Investigated



  • Gainsight Apps Allowed Unauthorized Access to Salesforce Data, Leading to Token Revocation and AppExchange Removal
  • Incident linked to August 2025 Salesloft breach where OAuth tokens exposed 1.5 billion records
  • ShinyHunters used stolen secrets to steal license and contact data from Gainsight customers

The Salesloft Drift incident appears to have reached Gainsight, causing hundreds more organizations to potentially lose their sensitive data to hackers.

Salesforce has confirmed that it saw “unusual activity” involving apps published by Gainsight connected to Salesforce.



Leave a Comment

Your email address will not be published. Required fields are marked *