2025 Gainsight / Salesforce ecosystem — OAuth token abuse after Salesloft-Drift style supply-chain wave
Data compromised
Salesforce-held CRM objects accessible through over-permissioned integration tokens—scope differs per tenant
Technical writeup
In late 2025, security researchers and trade press described attackers chaining compromised OAuth tokens—initially linked to an earlier Salesloft/Drift-class CRM integration incident—to abuse Gainsight’s connectors into customer Salesforce orgs. Google’s threat-intelligence commentary summarized in TechRadar estimated on the order of 200 Salesforce tenants could have been touched across the campaign, with actors branding themselves in niche reporting as “Scattered Lapsus$ Hunters” style personas. Actual per-tenant data categories vary; treat as SaaS supply-chain token replay rather than a single Gainsight database dump.
Root cause
Stolen third-party integration OAuth secrets replayed against Gainsight-Salesforce API trust
References
- https://www.techradar.com/pro/security/google-security-experts-say-gainsight-hacks-may-have-left-hundreds-of-companies-affected
- https://www.salesforceben.com/hackers-stole-data-from-200-companies-following-salesforce-gainsight-breach/
- https://www.reco.ai/blog/gainsight-oauth-attack-what-salesforce-users-must-do-now