← Gainsight

2025 Gainsight / Salesforce ecosystem — OAuth token abuse after Salesloft-Drift style supply-chain wave

2025 Unknown records affected Share on X

Data compromised

Salesforce-held CRM objects accessible through over-permissioned integration tokens—scope differs per tenant

Technical writeup

In late 2025, security researchers and trade press described attackers chaining compromised OAuth tokens—initially linked to an earlier Salesloft/Drift-class CRM integration incident—to abuse Gainsight’s connectors into customer Salesforce orgs. Google’s threat-intelligence commentary summarized in TechRadar estimated on the order of 200 Salesforce tenants could have been touched across the campaign, with actors branding themselves in niche reporting as “Scattered Lapsus$ Hunters” style personas. Actual per-tenant data categories vary; treat as SaaS supply-chain token replay rather than a single Gainsight database dump.

Root cause

Stolen third-party integration OAuth secrets replayed against Gainsight-Salesforce API trust

References