• News/
  • https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/

Salesforce investigates customer data theft via Gainsight breach

BleepingComputer
·
Sergiu Gatlan
·
Published Nov 20, 2025
·
Updated

Salesforce says it revoked refresh tokens linked to Gainsight-published applications while investigating a new wave of data theft attacks targeting customers. The cloud-based software company noted that this doesn't stem from a vulnerability in its customer relationship management (CRM) platform since all evidence points to the malicious activity being related to the app's external connection to Salesforce. "Salesforce has identified unusual activity involving Gainsight-published applications connected to Salesforce, which are installed and managed directly by customers. Our investigation indicates this activity may have enabled unauthorized access to certain customers' Salesforce data through the app's connection," it said in a Thursday morning advisory. "Upon detecting the activity, Salesforce revoked all active access and refresh tokens associated with Gainsight-published applications connected to Salesforce and temporarily removed those applications from the AppExchange while our investigation continues." Salesforce has alerted all impacted customers of this incident and advised those requiring further assistance to reach out to the Salesforce Help team. While the company hasn't provided more details regarding these attacks, this incident is similar to the August 2025 Salesloft breach, when an extortion group known as "Scattered Lapsus$ Hunters" stole sensitive information, including passwords, AWS access keys, and Snowflake tokens, from customers' Salesforce instances, ...

Read full article

Affected Software

2 affected components
Salesforce CRM
Gainsight Gainsight-published applications
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses Salesforce investigating customer data theft linked to a breach involving Gainsight applications.

2

What security implications are discussed?

The article highlights the risk of data theft impacting Salesforce customers due to vulnerabilities associated with Gainsight applications.

3

What actions has Salesforce taken in response to the breach?

Salesforce has revoked refresh tokens connected to Gainsight-published applications to mitigate the threat during the investigation.

4

What products or software are affected by the breach?

The breach affects Salesforce CRM and Gainsight-published applications.

5

Is there confirmation that the breach is due to a vulnerability in Salesforce products?

Salesforce stated that the breach does not stem from a vulnerability in their products.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203