EXCLUSIVE ShinyHunters has claimed responsibility for the Gainsight breach that allowed the data thieves to snarf data from hundreds more Salesforce customers. In messages sent to The Register, a member of the extortionist crew said they gained access to Gainsight during the Salesloft Drift hack earlier this year: "We've had access to Gainsight for nearly 3 months." "The data from Salesloft Drift breached has enabled entry points into so many systems. Very lucrative systems," a member of the cyber-gang claiming to be Shiny told The Register. "I do not like Salesforce at all, would be nice if they stopped acting all high and mighty and just pay to fix this mess." Gainsight did not respond to The Register's inquiries. The saga started back in March, when the intruders gained access to a Salesloft GitHub account and stole OAuth tokens from Salesloft Drift's integration with Salesforce. Drift, a third-party application used to automate sales processes, integrates with Salesforce via connected-app APIs to help manage leads and coordinate pitches, and compromising these OAuth security tokens allowed the data thieves to silently steal a ton of Salesforce customer data. According to ShinyHunters, they also gained access to Gainsight during the Drift breaches. Gainsight is a customer success platform that also integrates with Salesforce and several other CRMs, including HubSpot, as well as support tools like Zendesk. In a Friday alert, Gainsight said it brought on Google's Mandiant in...
ShinyHunters 'does not like Salesforce at all'
The Register
·Jessica Lyons
·Published Nov 21, 2025
·Updated
Affected Software
3 affected components
Salesforce Salesforce
Salesloft Drift
Gainsight Gainsight
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the Gainsight data breach claimed by the ShinyHunters group, impacting many Salesforce customers.
2
What security implications are discussed?
The breach raises concerns about the security of Salesforce customer data and the potential for further exploitation by attackers.
3
What products or software are affected?
The affected products include Salesforce and Gainsight, along with implications for associated tools like Salesloft and Drift.
4
Who is responsible for the breach?
The ShinyHunters cybercriminal group has claimed responsibility for the Gainsight breach.
5
How did the attackers gain access to the data?
The attackers reportedly gained access to sensitive customer data through a breach in the Gainsight platform.