Cybersecurity News Hub
No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
No Result
View All Result
Cybersecurity News Hub
No Result
View All Result
Home Data Breach

Salesforce customers face second third-party incident this year with Gainsight breach

Cyberinchief by Cyberinchief
November 21, 2025
Reading Time: 3 mins read
0
Salesforce customers face second third-party incident this year with Gainsight breach



Salesforce has launched an investigation into a spate of customer data theft incidents following a breach at a third-party application provider.

In a statement on Thursday 20 November, the CRM giant revealed it had revoked access and refresh tokens for Gainsight-published applications as part of its response to the breach.

Gainsight is a software as a service (SaaS) provider specializing in customer success and product experience, available to Salesforce customers via the company’s App Exchange platform.

RELATED POSTS

UK Hospital Asks Court to Stymie Ransomware Data Leak

These five countries recorded the most third-party data breaches last year

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

“Salesforce has identified unusual activity involving Gainsight-published applications connected to Salesforce, which are installed and managed directly by customers,” the company said in an advisory.

Salesforce noted that a preliminary investigation suggests the breach could have enabled “unauthorized access to certain customers’ Salesforce data” through Gainsight connections.

“Upon detecting the activity, Salesforce revoked all active access and refresh tokens associated with Gainsight-published applications connected to Salesforce and temporarily removed those applications from the AppExchange while our investigation continues,” the advisory added.

Exact details on the scope of the incident and those affected are yet to be revealed. However, Salesforce confirmed that affected customers have been notified.

Sign up today and you will receive a free copy of our Future Focus 2025 report – the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives

Gainsight the latest third-party incident for Salesforce

The Gainsight incident marks the latest third-party application breach for Salesforce in recent months.

Buy JNews
ADVERTISEMENT

Earlier this year, the Salesloft Drift attack impacted hundreds of companies including Google, Zscaler, Cloudflare, and Palo Alto Networks.

Hackers gained access to sensitive customer data through compromised OAuth tokens associated with the third-party application.

Brian Soby, CTO and co-founder at AppOmni, said the scale of Gainsight integrations means this latest incident could have equally wide-reaching implications for an array of businesses.

“Gainsight is widely deployed and tightly connected to Salesforce, Slack, Google, Microsoft, and numerous other SaaS environments,” he said. “Because of that footprint, customers now have to quickly identify every location where Gainsight was integrated.”

Soby added that the Gainsight incident once again highlights “persistent weaknesses” in SaaS supply chain security practices.

“The attack closely mirrors the earlier Drift breach, which also targeted Salesforce, Google Workspace, and other widely used SaaS platforms,” he told ITPro.

“The scale of the Gainsight compromise underscores that many organizations did not apply the lessons they should have learned from Drift, leaving large portions of their SaaS supply chain exposed.”

Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.

MORE FROM ITPRO



Source link

Tags: breachcustomersFaceGainsightIncidentSalesforcethirdpartyyear
ShareTweetPin
Cyberinchief

Cyberinchief

Related Posts

UK Hospital Asks Court to Stymie Ransomware Data Leak
Data Breach

UK Hospital Asks Court to Stymie Ransomware Data Leak

December 8, 2025
These five countries recorded the most third-party data breaches last year
Data Breach

These five countries recorded the most third-party data breaches last year

December 8, 2025
LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net
Data Breach

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

December 7, 2025
Rethinking the CIO-CISO Dynamic in the Age of AI
Data Breach

Rethinking the CIO-CISO Dynamic in the Age of AI

December 6, 2025
NHS supplier hit with £3m fine for security failings that led to attack
Data Breach

NHS supplier hit with £3m fine for security failings that led to attack

December 6, 2025
HHS Outlines AI Road Map Amid Major Department Overhaul
Data Breach

HHS Outlines AI Road Map Amid Major Department Overhaul

December 5, 2025
Next Post
ట్రైనింగ్ ఇచ్చి 100% జాబ్ అవకాశం | Cyber Security Course 2025 | Latest Jobs in Telugu

ట్రైనింగ్ ఇచ్చి 100% జాబ్ అవకాశం | Cyber Security Course 2025 | Latest Jobs in Telugu

।ଭାରତରେ ମୋବାଇଲ୍ ଠକେଇକୁ ଏଡାଇବା ପାଇଁ ହେଲ୍ପଲାଇନ ନମ୍ବର | Cyber Crime Helpline Number #shorts #cybercrime

।ଭାରତରେ ମୋବାଇଲ୍ ଠକେଇକୁ ଏଡାଇବା ପାଇଁ ହେଲ୍ପଲାଇନ ନମ୍ବର | Cyber Crime Helpline Number #shorts #cybercrime

Recommended Stories

Nearly all of the top US banks were impacted by third party breaches last year

Nearly all of the top US banks were impacted by third party breaches last year

November 14, 2025
A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do

A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do

October 31, 2025
cybersecurity || cyberforensics || quantumcomputing || computerengineering || informationtechnology

cybersecurity || cyberforensics || quantumcomputing || computerengineering || informationtechnology

October 26, 2025

Popular Stories

  • Allianz Life – 1,115,061 breached accounts

    Allianz Life – 1,115,061 breached accounts

    0 shares
    Share 0 Tweet 0
  • Prosper – 17,605,276 breached accounts

    0 shares
    Share 0 Tweet 0
  • साइबर अपराध | Illegal Payment Gateway & Rented Bank Accounts | MAMTA CHOPRA

    0 shares
    Share 0 Tweet 0
  • Miljödata – 870,108 breached accounts

    0 shares
    Share 0 Tweet 0
  • Snowflake Data Breach Explained: Lessons and Protection Strategies

    0 shares
    Share 0 Tweet 0

Search

No Result
View All Result

Recent Posts

  • Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
  • Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
  • Polisi kembali ungkap sindikat Cyber Crime kejahatan Internasional – iNews Malam 09/03

Categories

  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos

Newsletter

© 2025 All rights reserved by cyberinchief.com

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us

© 2025 All rights reserved by cyberinchief.com

Newsletter Signup

Subscribe to our weekly newsletter below and never miss the latest News.

Enter your email address

Thanks, I’m not interested