Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    BAFTA reaches three diversity targets set in 2020 across film, TV, and games

    Saudi Arabia’s PIF will own over 93.4% of EA if the deal completes

    UK Games Industry Shadow Council forms to address “good and poor practices” in sector

    Facebook X (Twitter) Instagram
    • Artificial Intelligence
    • Business Technology
    • Cryptocurrency
    • Gadgets
    • Gaming
    • Health
    • Software and Apps
    • Technology
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Tech AI Verse
    • Home
    • Artificial Intelligence

      Apple’s AI chief abruptly steps down

      December 3, 2025

      The issue that’s scrambling both parties: From the Politics Desk

      December 3, 2025

      More of Silicon Valley is building on free Chinese AI

      December 1, 2025

      From Steve Bannon to Elizabeth Warren, backlash erupts over push to block states from regulating AI

      November 23, 2025

      Insurance companies are trying to avoid big payouts by making AI safer

      November 19, 2025
    • Business

      Public GitLab repositories exposed more than 17,000 secrets

      November 29, 2025

      ASUS warns of new critical auth bypass flaw in AiCloud routers

      November 28, 2025

      Windows 11 gets new Cloud Rebuild, Point-in-Time Restore tools

      November 18, 2025

      Government faces questions about why US AWS outage disrupted UK tax office and banking firms

      October 23, 2025

      Amazon’s AWS outage knocked services like Alexa, Snapchat, Fortnite, Venmo and more offline

      October 21, 2025
    • Crypto

      Cardano Builders are Now Betting on AI and Quantum Computing Growth

      December 6, 2025

      Zcash Price Struggle Below $400 Is Down To Bitcoin, Here’s How

      December 6, 2025

      Tom Lee’s BitMine Extends Ethereum Bet With $200 Million in Two Days

      December 6, 2025

      This December Could Decide the Fate of Digital Asset Treasuries: Here’s CoinShares’ Survival Warning

      December 6, 2025

      Will Solana’s Price Trajectory Be Defined By Losses?

      December 6, 2025
    • Technology

      Judge puts a one-year limit on Google’s contracts for default search placement

      December 7, 2025

      Apple’s Johny Srouji could continue the company’s executive exodus, according to report

      December 7, 2025

      Waymo’s robotaxi fleet is being recalled again, this time for failing to stop for school buses

      December 7, 2025

      Meta plans to push back the debut of its next mixed reality glasses to 2027

      December 7, 2025

      Engadget review recap: Dell 16 Premium, Nikon ZR, Ooni Volt 2 and more

      December 7, 2025
    • Others
      • Gadgets
      • Gaming
      • Health
      • Software and Apps
    Check BMI
    Tech AI Verse
    You are at:Home»Technology»Salesforce investigates customer data theft via Gainsight breach
    Technology

    Salesforce investigates customer data theft via Gainsight breach

    TechAiVerseBy TechAiVerseNovember 21, 2025No Comments3 Mins Read0 Views
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Reddit
    Salesforce investigates customer data theft via Gainsight breach
    Share
    Facebook Twitter LinkedIn Pinterest WhatsApp Email

    Salesforce investigates customer data theft via Gainsight breach

    Salesforce says it revoked refresh tokens linked to Gainsight-published applications while investigating a new wave of data theft attacks targeting customers.

    The cloud-based software company noted that this doesn’t stem from a vulnerability in its customer relationship management (CRM) platform since all evidence points to the malicious activity being related to the app’s external connection to Salesforce.

    “Salesforce has identified unusual activity involving Gainsight-published applications connected to Salesforce, which are installed and managed directly by customers. Our investigation indicates this activity may have enabled unauthorized access to certain customers’ Salesforce data through the app’s connection,” it said in a Thursday morning advisory.

    “Upon detecting the activity, Salesforce revoked all active access and refresh tokens associated with Gainsight-published applications connected to Salesforce and temporarily removed those applications from the AppExchange while our investigation continues.”

    Salesforce has alerted all impacted customers of this incident and advised those requiring further assistance to reach out to the Salesforce Help team.

    While the company hasn’t provided more details regarding these attacks, this incident is similar to the August 2025 Salesloft breach, when an extortion group known as “Scattered Lapsus$ Hunters” stole sensitive information, including passwords, AWS access keys, and Snowflake tokens, from customers’ Salesforce instances, using stolen OAuth tokens for Salesloft’s Drift AI chat integration with Salesforce.

    The ShinyHunters extortion group told BleepingComputer at the time that the Salesloft data theft attacks affected around 760 companies, resulting in the theft of 1.5 billion Salesforce records.

    Companies known to have been impacted in the Salesloft attacks include Google, Cloudflare, Rubrik, Elastic, Proofpoint, JFrog, Zscaler, Tenable, Palo Alto Networks, CyberArk, BeyondTrust, Nutanix, Qualys, and Cato Networks, among many others.

    Today, in messages exchanged with BleepingComputer, ShinyHunters claimed they gained access to another 285 Salesforce instances after breaching Gainsight via secrets stolen in the Salesloft drift breach.

    Gainsight previously confirmed it was breached via stolen OAuth tokens linked to Salesloft Drift and said the attackers accessed business contact details, including names, business email addresses, phone numbers, regional/location details, licensing information, and support case contents.

    BleepingComputer reached out to Gainsight with questions about the data theft attacks related to Gainsight applications, but a response was not immediately available.

    7 Security Best Practices for MCP

    As MCP (Model Context Protocol) becomes the standard for connecting LLMs to tools and data, security teams are moving fast to keep these new services safe.

    This free cheat sheet outlines 7 best practices you can start using today.

    Share. Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Telegram Email
    Previous ArticleNew SonicWall SonicOS flaw allows hackers to crash firewalls
    Next Article GlobalProtect VPN portals probed with 2.3 million scan sessions
    TechAiVerse
    • Website

    Jonathan is a tech enthusiast and the mind behind Tech AI Verse. With a passion for artificial intelligence, consumer tech, and emerging innovations, he deliver clear, insightful content to keep readers informed. From cutting-edge gadgets to AI advancements and cryptocurrency trends, Jonathan breaks down complex topics to make technology accessible to all.

    Related Posts

    Judge puts a one-year limit on Google’s contracts for default search placement

    December 7, 2025

    Apple’s Johny Srouji could continue the company’s executive exodus, according to report

    December 7, 2025

    Waymo’s robotaxi fleet is being recalled again, this time for failing to stop for school buses

    December 7, 2025
    Leave A Reply Cancel Reply

    Top Posts

    Ping, You’ve Got Whale: AI detection system alerts ships of whales in their path

    April 22, 2025485 Views

    Lumo vs. Duck AI: Which AI is Better for Your Privacy?

    July 31, 2025165 Views

    6.7 Cummins Lifter Failure: What Years Are Affected (And Possible Fixes)

    April 14, 202586 Views

    Is Libby Compatible With Kobo E-Readers?

    March 31, 202563 Views
    Don't Miss
    Gaming December 7, 2025

    BAFTA reaches three diversity targets set in 2020 across film, TV, and games

    BAFTA reaches three diversity targets set in 2020 across film, TV, and games Organisation to…

    Saudi Arabia’s PIF will own over 93.4% of EA if the deal completes

    UK Games Industry Shadow Council forms to address “good and poor practices” in sector

    Ron Gilbert cancels RPG project due to lack of support and funding

    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us
    About Us

    Welcome to Tech AI Verse, your go-to destination for everything technology! We bring you the latest news, trends, and insights from the ever-evolving world of tech. Our coverage spans across global technology industry updates, artificial intelligence advancements, machine learning ethics, and automation innovations. Stay connected with us as we explore the limitless possibilities of technology!

    Facebook X (Twitter) Pinterest YouTube WhatsApp
    Our Picks

    BAFTA reaches three diversity targets set in 2020 across film, TV, and games

    December 7, 20250 Views

    Saudi Arabia’s PIF will own over 93.4% of EA if the deal completes

    December 7, 20250 Views

    UK Games Industry Shadow Council forms to address “good and poor practices” in sector

    December 7, 20250 Views
    Most Popular

    Apple thinks people won’t use MagSafe on iPhone 16e

    March 12, 20250 Views

    Volkswagen’s cheapest EV ever is the first to use Rivian software

    March 12, 20250 Views

    Startup studio Hexa acquires majority stake in Veevart, a vertical SaaS platform for museums

    March 12, 20250 Views
    © 2025 TechAiVerse. Designed by Divya Tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions

    Type above and press Enter to search. Press Esc to cancel.