HomeSecurityGainsight expands list of affected customers

Gainsight expands list of affected customers

Gainsight has revealed that recent suspicious activity targeting its apps has affected more customers than initially estimated. The company said Salesforce initially provided a list of three affected customers, which has since been expanded to include November 21, 2025.

See also: Gainsight breach: Salesforce investigates possible data theft

Gainsight

It did not disclose the exact number of customers affected, but its CEO, Chuck Ganapathi, said: “We are currently aware of only a few customers whose data was affected.” This development follows Salesforce’s warning about detecting “unusual activity” related to apps published by Gainsight and connected to the platform, leading the company to revoke all access and refresh tokens associated with them.

The breach was claimed by a notorious cybercrime group known as ShinyHunters (also referred to as Bling Libra). Several precautionary measures have been taken to contain the incident. This includes temporarily suspending Gainsight integrations with Zendesk, Gong.io , and HubSpot , and disabling Google OAuth clients with callback URIs such as gainsightcloud.com. HubSpot, in its advisory, stated that it has found no evidence to suggest any breach of its own infrastructure or that of its customers.

In an FAQ, Gainsight listed the products for which Salesforce read and write capabilities have been temporarily unavailable: – Customer Success (CS) – Northpass – Customer Education (CE). The company stressed that Staircase is not affected by the incident, although Salesforce has removed the Staircase connection as a precaution in response to an ongoing investigation. Both Salesforce and Gainsight have published indicators of compromise (IoCs) regarding the incident. A user agent string, “Salesforce-Multi-Org-Fetcher/1.0,” used for unauthorized access was also noted as previously used in the Salesloft Drift activity.

See also: Scattered Lapsus$ Hunters claim to have stolen over 1 billion Salesforce files

Gainsight expands list of affected customers

According to information from Salesforce, identification attempts against customers with compromised Gainsight access tokens were first recorded from the IP address “3.239.45.43” on October 23, 2025, followed by subsequent waves of identification and unauthorized access that began on November 8. To further secure their environments, customers are advised to take the following steps:

  • – Rotate S3 bucket access keys and other connectors such as BigQuery, Zuora, Snowflake, etc., used for connections to Gainsight.
  • – Connect directly to Gainsight NXT, instead of through Salesforce, until the integration is fully restored.
  • – Reset NXT user passwords for any users who are not authenticated via SSO.
  • – Reauthorize any connected apps or integrations that rely on user credentials or tokens.

“These steps are proactive in nature and are designed to ensure your environment remains secure while the investigation continues,” Gainsight said. This development comes as part of a new ransomware-as-a-service (RaaS) platform called ShinySp1d3r, which is being developed by Scattered Spider, LAPSUS$, and ShinyHunters. Data from ZeroFox has revealed that this cybercrime alliance is responsible for at least 51 cyberattacks in the past year.

See also: Scattered Lapsus$ Hunters: Salesforce data leak site – 39 companies victims

Gainsight expands list of affected customers

These features include hooking the EtwEventWrite to prevent logging by the Windows Event Viewer, terminating processes that hold files open to allow encryption, and filling free space on a disk by writing random data contained in a .tmp file, presumably to overwrite any deleted files. ShinySp1d3r also has the ability to search for open network shares and encrypt them, as well as spread to other devices on the local network via various deployment methods.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS