Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Benchmark raises $225 million in special funding to double Cerebras

From Svedka to Anthropic, brands are boldly leveraging AI in their Super Bowl ads

Prince Andrew’s advisor encouraged Jeffrey Epstein to invest in EV startups like Lucid Motors

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Google says hackers stole data from 200 companies after Gainsight breach
Startups

Google says hackers stole data from 200 companies after Gainsight breach

userBy userNovember 21, 2025No Comments4 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Google has admitted that hackers stole more than 200 companies’ data stored in Salesforce in a massive supply chain hack.

Salesforce said Thursday that “Salesforce data for certain customers” had been compromised, although it did not name the affected companies. The data was stolen through an app published by Gainsight, which provides a customer support platform for other companies.

Austin Larsen, principal threat analyst at Google Threat Intelligence Group, said in a statement that the company is “aware of over 200 Salesforce instances that may be affected.”

After Salesforce announced the breach, a notorious and somewhat obscure hacking group known as Scattered Lapsus$ Hunters (which also includes the ShinyHunters gang) claimed responsibility for the hack on its Telegram channel, which was witnessed by TechCrunch.

The hacker group claimed responsibility for hacks that affected Atlassian, CrowdStrike, Docusign, F5, GitLab, Linkedin, Malwarebytes, SonicWall, Thomson Reuters, and Verizon.

inquiry

Do you have more information about these Salesforce and Gainsight data breaches? Or any other data breach? You can contact Lorenzo Franceschi-Bicchierai securely from a non-work device on Signal (+1 917 257 1382) or on Telegram and Keybase @lorenzofb or by email.

Google will not comment on specific victims.

CrowdStrike spokesperson Kevin Benacci told TechCrunch in a statement that the company is “not affected by the Gainsight issue and all customer data remains secure.” CrowdStrike confirmed to TechCrunch that it fired a “suspicious insider” who allegedly passed information to the hackers.

TechCrunch reached out to all the companies mentioned by Scattered Lapsus$ Hunters.

Verizon spokesperson Kevin Israel said in a statement that “Verizon is aware of the unsubstantiated claims made by threat actors,” but provided no evidence of the claims.

Malwarebytes spokesperson Ashley Stewart told TechCrunch that the company’s security team is “aware” of the issue with Gainsight and Salesforce and is “actively investigating the issue.”

A Thomson Reuters spokeswoman said the company was “actively investigating” the matter.

As of publication, the other companies had not responded to requests for comment.

Hackers from the ShinyHunters group told TechCrunch in an online chat that they gained access to Gainsight thanks to a previous hacking campaign targeting customers of Salesloft, an AI and chatbot-powered marketing platform called Drift. In previous cases, hackers stole Drift authentication tokens from those customers, allowing them to compromise the linked Salesforce instance and download its content.

At the time, Gainsight acknowledged that it was one of the victims of its hacking campaign.

“Gainsight was a customer of Salesloft Drift, but they were affected and therefore fully compromised by us,” a ShinyHunters group spokesperson told TechCrunch.

“As a matter of policy, Salesforce does not comment on specific customer issues,” Salesforce spokesperson Nicole Aranda told TechCrunch.

Gainsight did not respond to TechCrunch’s request for comment.

Salesforce on Thursday effectively distanced itself from the customer data breach, saying there is “no indication that this issue is due to a vulnerability in the Salesforce platform.”

Gainsight provides up-to-date information about incidents on our Incidents page. On Friday, the company announced that it is currently working with Mandiant, Google’s incident response arm, to help investigate the breach, that the incident in question “resulted from the application’s external connectivity, and not from any issues or vulnerabilities within the Salesforce platform,” and that “forensic analysis is ongoing as part of a comprehensive and independent review.”

“Salesforce has temporarily revoked active access tokens for Gainsight-connected applications as a precaution while the investigation into anomalous activity continues,” according to Gainsight’s incident page, which said Salesforce is notifying affected customers whose data was stolen.

The Scattered Rapsusdor Hunters said on their Telegram channel that they plan to launch a dedicated website by next week to blackmail victims of the latest campaign. This is the group’s modus operandi. In October, hackers released a similar extortion website after stealing victims’ Salesforce data in the Salesloft scandal.

Scattered Lapsus$ Hunters is an English-speaking hacker collective comprised of several cybercriminal organizations, including ShinyHunters, Scattered Spider, and Lapsus$, whose members use social engineering tactics to trick company employees into allowing hackers to access their systems and databases. Over the past few years, these groups have killed several high-profile victims, including MGM Resorts, Coinbase, and DoorDash.

This article has been updated with comment from Thomson Reuters and Verizon.


Source link

#Aceleradoras #CapitalRiesgo #EcosistemaStartup #Emprendimiento #InnovaciónEmpresarial #Startups
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleGrafana patch CVSS 10.0 SCIM flaw allows impersonation and privilege escalation
Next Article Scientists discover rare northern whale alive in the ocean for the first time and shoot it with a crossbow
user
  • Website

Related Posts

Benchmark raises $225 million in special funding to double Cerebras

February 7, 2026

From Svedka to Anthropic, brands are boldly leveraging AI in their Super Bowl ads

February 6, 2026

Prince Andrew’s advisor encouraged Jeffrey Epstein to invest in EV startups like Lucid Motors

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Benchmark raises $225 million in special funding to double Cerebras

From Svedka to Anthropic, brands are boldly leveraging AI in their Super Bowl ads

Prince Andrew’s advisor encouraged Jeffrey Epstein to invest in EV startups like Lucid Motors

AI agents could become lawyers after all

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.