Salesforce is investigating unauthorized access to customer data linked to Gainsight-published applications. The company revoked all active access and refresh tokens tied to these apps and removed them from the AppExchange during the investigation. Evidence shows the breach did not come from Salesforce’s core CRM platform but from external OAuth connections. Early signs match patterns seen in the August 2025 Salesloft breach, where attackers used stolen tokens to siphon massive volumes of customer records.
Relevant Source (Cybersecurity Dive): Salesforce Investigating Campaign Targeting Customer Environments Connected To Gainsight App
This report covers Salesforce’s investigation into unauthorized access via Gainsight-published apps, including token revocation, impact on customer environments, and links to ShinyHunters’ OAuth-focused attacks.
Quick Facts
- Unauthorized access tied to Gainsight-connected Salesforce apps
- Salesforce revoked all active Gainsight OAuth tokens
- No Salesforce CRM platform vulnerability identified
- Similar tactic to Salesloft’s 2025 OAuth token breach
- ShinyHunters claims access to another 285 Salesforce instances
- Gainsight confirms attackers accessed business contact data
OAuth Risk Exposure
Unauthorized access came through external OAuth-linked apps rather than Salesforce’s native infrastructure. This type of breach occurs when attackers obtain refresh tokens or secrets tied to third-party integrations. Once inside, they can pull sensitive records without tripping basic authentication controls. Gainsight’s exposure appears to be downstream from the Salesloft Drift AI breach where OAuth tokens were previously stolen.
- Attackers leveraged OAuth tokens tied to Gainsight apps
- Gainsight apps were removed from AppExchange during investigation
- Salesforce alerted all customers with affected connections
Salesforce’s core security controls remained intact, but OAuth chains are only as strong as the external apps that link into them.
Relevant Source (Google Threat Intelligence Group): Widespread Data Theft Targets Salesforce Instances via Salesloft Drift
This advisory breaks down how attackers used compromised OAuth tokens from the Salesloft Drift app to access Salesforce instances, illustrating the exact token-abuse pattern behind the current OAuth risk exposure.
Relevant Source (CSO Online): OAuth token compromise hits Salesforce ecosystem again, Gainsight impacted
This report covers the latest Salesforce and Gainsight incident, detailing how stolen OAuth tokens tied to third-party apps enabled unauthorized data access even though Salesforce’s core platform was not directly breached.
Security Impact
The breach matters because OAuth tokens grant wide, persistent access inside Salesforce environments. Attackers used these tokens to steal data from hundreds of companies during the Salesloft incident. ShinyHunters now claims they expanded that access through Gainsight, creating another large downstream blast radius. Stolen records often include contact data, internal notes, licensing information, and support content.
- OAuth tokens provide long-lived access
- Breaches spread across interconnected vendors
- Large volumes of data can be exfiltrated quietly
- Attackers target CRM systems for high-value records
- Previous attacks impacted more than 760 organizations
The expanding chain of compromise highlights the risk that comes with trusted third-party integrations.
Relevant Source (Google Threat Intelligence Group): Widespread Data Theft Targets Salesforce Instances via Salesloft Drift
This advisory details how attackers used compromised OAuth tokens from the Salesloft Drift integration to exfiltrate large volumes of Salesforce data, showing how long-lived tokens enable quiet, large-scale data theft.
Relevant Source (Palo Alto Networks Unit 42): Token Management In The Third-Party Supply Chain
This research explains how stolen or poorly managed OAuth tokens in third-party integrations let attackers enumerate CRM data and execute supply chain style breaches across many downstream customers.

Steps To Take
Organizations that rely on Gainsight or similar connected tools should verify their integrations immediately. Admins should review connected apps, revoke unnecessary tokens, and audit recent access logs for irregular pulls of CRM data. Multi-layer token management and tighter scopes reduce the chance of attackers exploiting integration pathways.
- Review all Salesforce connected apps
- Revoke and reauthorize integrations with fresh tokens
- Audit access logs for unusual API activity
- Limit OAuth scopes to minimum required
- Rotate keys and secrets on all connected platforms
A full integration review strengthens your position against token theft and cross-platform breach paths.
Relevant Source (CISA): Securing Core Cloud Identity Infrastructure: Addressing Advanced Threats Through Public-Private Collaboration
This guidance stresses strong identity controls, token hygiene, and continuous monitoring across cloud services, aligning with steps like auditing access, rotating secrets, and tightening app permissions.
Relevant Source (Salesforce): Manage OAuth Access Policies for a Connected App
This Salesforce help article explains how to control connected app access, set token lifetimes, restrict users and IP ranges, and manage OAuth scopes, directly supporting the recommended hardening steps for Salesforce integrations.
The Big Picture
OAuth-based attacks continue to spread through the enterprise ecosystem because many companies rely heavily on third-party platforms to expand Salesforce functionality. Each integration brings its own security posture which becomes part of the organization’s risk profile. Attackers understand this and now focus on token theft rather than platform exploits.
Salesforce’s quick removal of Gainsight apps and token revocation shows how interconnected vendors can amplify both convenience and vulnerability. The Salesloft and Gainsight events highlight a pattern where a single OAuth breach can ripple through hundreds of organizations.
Relevant Source (UK NCSC): Understanding The Threat To The Supply Chain
This guidance explains how third-party suppliers and SaaS integrations expand an organization’s attack surface and why weaknesses in one vendor can ripple through the entire ecosystem.
Conclusion
Salesforce’s investigation into the Gainsight-linked breach reinforces the need to treat OAuth tokens as high-risk credentials. Organizations should assume that third-party integrations require the same scrutiny as internal systems. Tight controls, limited scopes, and routine token rotation can reduce the damage when attackers compromise connected platforms.
Common Questions
Are Salesforce’s core systems vulnerable?
No. Salesforce states the breach came from external OAuth connections, not the CRM platform itself.
What data was exposed?
Gainsight says attackers accessed business contact details and support case data. The exact impact varies by customer.
Who is behind these attacks?
ShinyHunters claims responsibility and previously targeted Salesloft in August 2025.
How many organizations were affected?
ShinyHunters claims access to another 285 Salesforce instances through Gainsight connections.
Should admins revoke tokens?
Yes. Salesforce already revoked Gainsight-related tokens, but organizations should audit and rotate all connected app tokens.
How JENI Helps Strengthen Security Hygiene
JENI supports a cleaner and more resilient system by helping users reduce routine maintenance gaps that attackers often exploit. The software improves day to day stability and keeps devices running in predictable condition. A stable machine lowers the chance of unnoticed background processes masking suspicious behavior.
Key Ways JENI Improves System Health
- Real time cleanup that prevents clutter from slowing security tools
- Smart monitoring that helps keep storage and memory balanced
- Automated checks that catch early signs of strain or abnormal activity
JENI fits well in an environment where high trust integrations demand consistent system health. Strong hygiene reduces the noise that hides real problems and keeps attention on events that matter. Stable performance supports security workflows that rely on predictable behavior. JENI gives users a smoother and more controlled system that supports better security awareness.

