• News/
  • https://www.theregister.com/2025/11/21/shinyhunters_salesforce_gainsight_breach/

ShinyHunters 'does not like Salesforce at all'

The Register
·
Jessica Lyons
·
Published Nov 21, 2025
·
Updated

EXCLUSIVE ShinyHunters has claimed responsibility for the Gainsight breach that allowed the data thieves to snarf data from hundreds more Salesforce customers. In messages sent to The Register, a member of the extortionist crew said they gained access to Gainsight during the Salesloft Drift hack earlier this year: "We've had access to Gainsight for nearly 3 months." "The data from Salesloft Drift breached has enabled entry points into so many systems. Very lucrative systems," a member of the cyber-gang claiming to be Shiny told The Register. "I do not like Salesforce at all, would be nice if they stopped acting all high and mighty and just pay to fix this mess." Gainsight did not respond to The Register's inquiries. The saga started back in March, when the intruders gained access to a Salesloft GitHub account and stole OAuth tokens from Salesloft Drift's integration with Salesforce. Drift, a third-party application used to automate sales processes, integrates with Salesforce via connected-app APIs to help manage leads and coordinate pitches, and compromising these OAuth security tokens allowed the data thieves to silently steal a ton of Salesforce customer data. According to ShinyHunters, they also gained access to Gainsight during the Drift breaches. Gainsight is a customer success platform that also integrates with Salesforce and several other CRMs, including HubSpot, as well as support tools like Zendesk. In a Friday alert, Gainsight said it brought on Google's Mandiant in...

Read full article

Affected Software

3 affected components
Salesforce Salesforce
Salesloft Drift
Gainsight Gainsight
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the Gainsight data breach claimed by the ShinyHunters group, impacting many Salesforce customers.

2

What security implications are discussed?

The breach raises concerns about the security of Salesforce customer data and the potential for further exploitation by attackers.

3

What products or software are affected?

The affected products include Salesforce and Gainsight, along with implications for associated tools like Salesloft and Drift.

4

Who is responsible for the breach?

The ShinyHunters cybercriminal group has claimed responsibility for the Gainsight breach.

5

How did the attackers gain access to the data?

The attackers reportedly gained access to sensitive customer data through a breach in the Gainsight platform.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203