Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Salesforce Faces New Data Breach Linked to Gainsight Integration
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Salesforce Faces New Data Breach Linked to Gainsight Integration

Highlights

  • Salesforce customer data was exposed following unusual activity in Gainsight apps.

  • Similar recent incidents highlight vulnerabilities in third-party integrations.

  • Organizations should monitor, review, and secure all connected external applications.

Ethan Moreno
Last updated: 21 November, 2025 - 2:19 am 2:19 am
Ethan Moreno 7 minutes ago
Share
SHARE

Contents
How Did the Breach Occur and Which Products Are Affected?What Actions Did Companies Involved Take?Could More Services Be at Risk Beyond Salesforce?

A fresh wave of customer data concerns has hit Salesforce after unauthorized activity was detected in Gainsight applications integrated within Salesforce environments. Security teams discovered the unusual patterns late Wednesday, sparking alerts among businesses relying on third-party vendors for streamlined customer management. This development amplifies anxiety for organizations already addressing recent incidents tied to the platform. Users now grapple with questions surrounding the safety of interconnected applications, as the ripple effects may stretch beyond Salesforce itself to other services connected via Gainsight.

Recent reports about Salesforce’s security history indicate a pattern of vulnerabilities connected to third-party integrations. Earlier breaches, particularly involving Salesloft Drift and external connectors, impacted hundreds of organizations and prompted intensified scrutiny of OAuth practices. Previous incidents focused on similar threat actors who targeted authentication pathways, but the scope and downstream implications varied depending on the affected tools. Compared to past cases, this breach signals a broader risk for clients relying on interconnected ecosystems, and underscores how cross-platform integrations expand possible attack vectors.

How Did the Breach Occur and Which Products Are Affected?

The breach centered around unusual activity within Gainsight, which acts as a “customer success” software frequently paired with Salesforce for enhanced user experiences. Google’s Threat Intelligence Group identified that over 200 Salesforce instances might have been compromised through these connections. This episode mirrors a prior attack less than two months ago that affected more than 700 customers using Salesloft Drift integration with Salesforce. Both incidents have been associated with cybercriminal groups such as ShinyHunters or UNC6240, suggesting a systematic targeting of third-party connectors.

What Actions Did Companies Involved Take?

Salesforce responded promptly by revoking access tokens that facilitated the data connections between its platform and the third-party apps. Gainsight, meanwhile, alerted customers about failed Salesforce connections and stated it is actively collaborating with Salesforce in the investigation.

“We continue to work closely with Salesforce as they investigate the unusual activity that led to the revocation of access tokens for Gainsight-published applications,”

Gainsight explained in an update. In response to the ongoing probe, Gainsight temporarily withdrew its app from the Hubspot Marketplace, though it emphasized this was a precaution rather than a response to any observed suspicious activity in Hubspot.

Could More Services Be at Risk Beyond Salesforce?

The potential impact of the incident could extend to any platform to which Gainsight customers linked their accounts. While no unauthorized activity tied to Hubspot has been detected, precautionary measures are in place and concern remains for other possible integrations.

“No suspicious activity related to Hubspot has been observed at this point. These are precautionary steps only.”

As discovered with the Salesloft Drift breach, attackers may exploit vulnerabilities in interlinked platforms, affecting a wide network of organizations.

Risks associated with relying on multi-platform integrations have become more pronounced for Salesforce and its ecosystem partners. When authentication tokens or API connections become compromised, attackers can move laterally across various software environments, harvesting sensitive information from numerous customer accounts. Security best practices recommend regularly reviewing token permissions, deploying least-privilege access policies, and monitoring all external connections for anomalies. As investigations proceed, businesses should monitor vendor status pages, update affected credentials, and ensure audit trails are reviewed to spot unusual access as early as possible.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

FCC Plans to Overturn Biden-Era Telecom Cybersecurity Rules

Countries Hit Bulletproof Hosting Providers with Global Sanctions

Amazon Urges Security Teams to Tackle Cyber-Aided Kinetic Attacks

Hackers Hijack Ray AI Framework for Global Cryptojacking Operation

CISO Stress Rises as Security Teams Battle Growing Threats

Share This Article
Facebook Twitter Copy Link Print
Ethan Moreno
By Ethan Moreno
Ethan Moreno, a 35-year-old California resident, is a media graduate. Recognized for his extensive media knowledge and sharp editing skills, Ethan is a passionate professional dedicated to improving the accuracy and quality of news. Specializing in digital media, Moreno keeps abreast of technology, science and new media trends to shape content strategies.
Previous Article Tesla Deploys First Branded Supercharger at Florida Business
Next Article Foxconn and Intrinsic Launch Robotics Push for U.S. Manufacturing

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Foxconn and Intrinsic Launch Robotics Push for U.S. Manufacturing
AI
Tesla Deploys First Branded Supercharger at Florida Business
Electric Vehicle
Autonomous Excavators Move Thousands of Tons at Construction Sites
AI Robotics
Garmin Packs Sport Features Into Compact Vivoactive 6
Wearables
US Permits Advanced AI Chip Sales to Saudi Arabia and UAE Ventures
AI Technology
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?