Salesforce says customer data may be exposed in Gainsight incident – “unusual activity” under investigation


  • Gainsight apps enabled unauthorized Salesforce data access, requested token revocation and AppExchange removal
  • Incident linked to August 2025 Salesloft breach where OAuth tokens exposed 1.5 billion records
  • ShinyHunters used stolen secrets to steal Gainsight customer contact and license data

The Salesloft Drift incident appears to have seeped downstream into Gainsight, resulting in hundreds of organizations potentially losing their sensitive data to hackers.

Salesforce has confirmed that it saw “unusual activity” involving Gainsight-published applications connected to Salesforce.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top