Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Prince Andrew’s advisor encouraged Jeffrey Epstein to invest in EV startups like Lucid Motors

The Legal Revolution is Digital: Meet TwinH, Your AI Partner in the Courtroom of the Future

Reddit says it’s considering further acquisitions in ad tech and other areas

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Salesforce reports unauthorized data access via OAuth activity linked to Gainsight
Identity

Salesforce reports unauthorized data access via OAuth activity linked to Gainsight

userBy userNovember 21, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

November 21, 2025Ravi LakshmananData Breach / SaaS Security

Salesforce warned that it had detected “anomalous activity” related to Gainsight published applications connected to its platform.

“Our investigation revealed that this activity may have allowed unauthorized access to certain customers’ Salesforce data through app connections,” the company said in its advisory.

The cloud services company announced that it has taken steps to revoke all active access and refresh tokens associated with Gainsight published applications connected to Salesforce. We have also temporarily removed these applications from AppExchange as we continue our investigation.

Salesforce did not say how many customers were affected by the incident, but said it had notified them.

DFIR retainer service

“There is no indication that this issue is due to a vulnerability in the Salesforce platform,” the company added. “This activity appears to be related to your application’s external connection to Salesforce.”

Out of an abundance of caution, the Gainsight app has been temporarily removed from the HubSpot Marketplace. “This may also impact Oauth access for customer connections while the review is ongoing,” Gainsight said. “At this time, we have not observed any suspicious activity related to Hubspot.”

In a post shared on LinkedIn, Austin Larsen, lead threat analyst at Google Threat Intelligence Group (GTIG), described this as a “new campaign” targeting Gainsight published applications connected to Salesforce.

This activity is assessed to be associated with threat actors associated with the ShinyHunters (aka UNC6240) group and mirrors a similar series of attacks targeting Salesloft Drift instances in early August of this year.

According to DataBreaches.Net, ShinyHunters acknowledged the campaign and said that the Salesloft and Gainsight attack waves were able to steal data from approximately 1,000 organizations.

Interestingly, Gainsight previously stated that it was also one of the Salesloft Drift customers affected in the previous attack. However, it is not clear at this stage whether previous infringements were involved in this incident.

CIS build kit

In this hack, attackers accessed company contact details for Salesforce-related content, including name, company email address, phone number, region/location details, product license information, and support case content (no attachments).

“Attackers are increasingly targeting OAuth tokens from trusted third-party SaaS integrations,” Larsen noted.

In light of this malicious activity, organizations are encouraged to review all third-party applications connected to Salesforce, revoke tokens for unused or suspicious applications, and rotate credentials if an integration reports anomalies.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleScientists discover new lion’s roar
Next Article SEC drops SolarWinds lawsuit after years of high-stakes cybersecurity investigation
user
  • Website

Related Posts

The Legal Revolution is Digital: Meet TwinH, Your AI Partner in the Courtroom of the Future

February 6, 2026

China-linked DKnife AitM framework, routers targeted for traffic hijacking and malware distribution

February 6, 2026

CISA orders removal of unsupported edge devices to reduce risk to federal networks

February 6, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Prince Andrew’s advisor encouraged Jeffrey Epstein to invest in EV startups like Lucid Motors

The Legal Revolution is Digital: Meet TwinH, Your AI Partner in the Courtroom of the Future

Reddit says it’s considering further acquisitions in ad tech and other areas

Here’s how Roblox’s age check works

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.