Friday, September 11, 2026

Hackers Use Salesforce Gainsight Breach to Access Data from More Than 200 Companies

Salesforce has disclosed a significant security incident involving unauthorized access to customer data through compromised Gainsight-published applications.

The breach, detected in mid-November 2025, potentially exposed sensitive information from over 200 organizations that use the customer success platform integrated with Salesforce.

Threat actors linked to the notorious ShinyHunters group exploited OAuth tokens to gain unauthorized access to Salesforce customer instances via third-party application connections.

Salesforce Disables Gainsight Integration After Detecting Unusual Activity

On November 20, 2025, Salesforce took immediate action by disabling all connections between Gainsight-published applications and the Salesforce platform.

The company’s security team identified suspicious activity that enabled unauthorized access to specific customers’ Salesforce data through the app’s external connection.

Salesforce emphasized that the issue did not stem from any vulnerability in the Salesforce platform, but rather from compromised OAuth tokens used by the third-party integration.

The investigation revealed that attackers began reconnaissance activities as early as October 23, 2025, and that intensive unauthorized access attempts occurred between November 16 and November 19, 2025.

Customers will be unable to reconnect their Gainsight-published applications until Salesforce determines it is safe to restore service.

The company has already taken steps to revoke affected tokens and remove compromised applications from the AppExchange marketplace.

Security researchers from Google Threat Intelligence Group and Mandiant have been working alongside Salesforce to track the threat actors behind this campaign.

The attackers employed sophisticated techniques to conceal their activities, routing traffic through multiple VPN services, including Mullvad, Surfshark, Proton, and Tor networks.

Salesforce identified 15 distinct IP addresses associated with unauthorized access attempts, along with unusual user agent strings such as “python-requests/2.28.1” and “Salesforce-Multi-Org-Fetcher/1.0” that are not used by legitimate Gainsight applications.

The attackers utilized various proxy services, including IProxyShop, ProxySeller, and NSocks, to mask their origin and evade detection.

One of the earliest indicators appeared on October 23, 2025, via an AWS IP address conducting reconnaissance against customers with compromised Gainsight access tokens.

The threat actors demonstrated operational security awareness by rotating between different VPN providers and proxy services throughout their campaign.

This incident mirrors a similar attack pattern recently observed targeting Salesloft Drift integrations, suggesting adversaries are increasingly exploiting trusted third-party SaaS integrations.

The ShinyHunters connection adds concern, as this threat group has been involved in numerous high-profile data breaches targeting major technology companies.

Salesforce and Google recommend that all organizations using cloud-based SaaS platforms immediately audit their connected applications and review OAuth token permissions.

Companies should investigate and revoke tokens for unused or suspicious integrations, and implement continuous monitoring to detect anomalous activity.

Indicators of Compromise

IOC TypeValueFirst SeenLast SeenActivity
IP Address104.3.11.12025-11-082025-11-08AT&T IP reconnaissance
IP Address198.54.135.1482025-11-162025-11-16Mullvad VPN proxy
IP Address198.54.135.1972025-11-162025-11-16Mullvad VPN proxy
IP Address198.54.135.2052025-11-182025-11-18Mullvad VPN proxy
IP Address146.70.171.2162025-11-182025-11-18Mullvad VPN proxy
IP Address169.150.203.2452025-11-182025-11-18Surfshark VPN proxy
IP Address172.113.237.482025-11-182025-11-18NSocks VPN proxy
IP Address45.149.173.2272025-11-182025-11-18Surfshark VPN proxy
IP Address135.134.96.762025-11-192025-11-19IProxyShop VPN proxy
IP Address65.195.111.212025-11-192025-11-19IProxyShop VPN proxy
IP Address65.195.105.812025-11-192025-11-19Nexx VPN proxy
IP Address65.195.105.1532025-11-192025-11-19ProxySeller VPN proxy
IP Address45.66.35.352025-11-192025-11-19Tor VPN proxy
IP Address146.70.174.692025-11-192025-11-19Proton VPN proxy
IP Address82.163.174.832025-11-192025-11-19ProxySeller VPN proxy
IP Address3.239.45.432025-10-232025-10-23AWS IP reconnaissance
User Agentpython-requests/2.28.12025-11-082025-11-08Unexpected user agent
User Agentpython-requests/2.32.32025-11-162025-11-16Unexpected user agent
User Agentpython/3.11 aiohttp/3.13.12025-10-232025-10-23Unexpected user agent
User AgentSalesforce-Multi-Org-Fetcher/1.02025-11-182025-11-19Threat actor tool

Organizations potentially affected should expect direct notification from Salesforce and Mandiant and monitor official security advisories for ongoing updates.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and set GBH as a Preferred Source in Google.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News