{"id":206446,"date":"2025-11-20T19:12:56","date_gmt":"2025-11-20T19:12:56","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/11\/20\/salesforce-says-some-of-its-customers-data-was-accessed-after-gainsight-breach-techcrunch\/"},"modified":"2025-11-20T19:12:56","modified_gmt":"2025-11-20T19:12:56","slug":"salesforce-says-some-of-its-customers-data-was-accessed-after-gainsight-breach-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2025\/11\/20\/salesforce-says-some-of-its-customers-data-was-accessed-after-gainsight-breach-techcrunch\/","title":{"rendered":"Salesforce says some of its customers&#8217; data was accessed after Gainsight breach | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Salesforce said on Wednesday that it\u2019s investigating a breach of \u201ccertain customers\u2019 Salesforce data\u201d that was compromised through apps published by Gainsight, a company that sells a platform for other companies to manage their customers.\u00a0<\/p>\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/status.salesforce.com\/generalmessages\/20000233\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">In a notice published late Wednesday<\/a>, Salesforce said the hacks involve \u201cGainsight-published applications connected to Salesforce, which are installed and managed directly by customers.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Salesforce said that there is \u201cno indication that this issue resulted from any vulnerability in the Salesforce platform,\u201d and that the activity appears related to Gainsight\u2019s \u201cexternal connection to Salesforce.\u201d<\/p>\n<p class=\"wp-block-paragraph\">When reached for comment, Salesforce spokesperson Nicole Aranda referred TechCrunch to the company\u2019s page dedicated to the incident.\u00a0<\/p>\n<div class=\"article-block block--callout block--right has-green-500-background-color\">\n<h4 class=\"block--callout__title\">Contact Us<\/h4>\n<p>\t\t\tDo you have more information about these Salesforce and Gainsight data breaches? Or other data breaches? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or <a href=\"https:\/\/techcrunch.com\/2025\/11\/20\/salesforce-says-some-of-its-customers-data-was-accessed-after-gainsight-breach\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">email<\/a><a href=\"https:\/\/techcrunch.com\/2025\/11\/20\/salesforce-says-some-of-its-customers-data-was-accessed-after-gainsight-breach\/mailto:lorenzo@techcrunch.com\/\" target=\"_blank\" rel=\"noopener\">.<\/a> You also can contact TechCrunch via <a href=\"https:\/\/techcrunch.com\/got-a-tip\/\" target=\"_blank\" rel=\"noopener\">SecureDrop<\/a>.\t\t<\/div>\n<p class=\"wp-block-paragraph\">As of this writing, Gainsight said <a href=\"https:\/\/status.gainsight.com\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">in a status page<\/a> that it is investigating a \u201cSalesforce connection issue,\u201d without making any reference to a potential breach. \u201cOur internal investigation is ongoing,\u201d Gainsight wrote.<\/p>\n<p class=\"wp-block-paragraph\">A spokesperson for Gainsight did not immediately respond to TechCrunch\u2019s request for comment.<\/p>\n<p class=\"wp-block-paragraph\">On its website, Gainsight touts several corporate customers, including Airtable, Notion, GitLab, and others. When reached by email, GitLab spokesperson Emily James told TechCrunch that GitLab\u2019s \u201csecurity team is investigating and we\u2019ll get back to you when we have more to share.\u201d<\/p>\n<div class=\"wp-block-techcrunch-inline-cta\">\n<div class=\"inline-cta__wrapper\">\n<p>Techcrunch event<\/p>\n<div class=\"inline-cta__content\">\n<p>\n\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__location\">San Francisco<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__separator\">|<\/span><br \/>\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"inline-cta__date\">October 13-15, 2026<\/span>\n\t\t\t\t\t\t\t<\/p>\n<\/p><\/div>\n<\/p><\/div>\n<\/div>\n<p class=\"wp-block-paragraph\">The prolific hacking group ShinyHunters <a href=\"https:\/\/databreaches.net\/2025\/11\/20\/threat-actors-have-reportedly-launched-yet-another-campaign-involving-an-application-connected-to-salesforce\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">told cybersecurity news website <\/a><a href=\"http:\/\/databreaches.net\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">DataBreaches.net<\/a> that it was behind the breach, adding that if Salesforce doesn\u2019t negotiate with them, they will create a new website to advertise the stolen data \u2014 a common extortion tactic by financially-motivated cybercriminals.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cThe next [data leak site] will contain the data of the Salesloft and GainSight campaigns,\u201d the hackers told DataBreaches.net. The hackers claim to have stolen data from close to a thousand companies.<\/p>\n<p class=\"wp-block-paragraph\">This data breach appears similar to an August breach at <a href=\"https:\/\/techcrunch.com\/2025\/09\/08\/salesloft-says-drift-customer-data-thefts-linked-to-march-github-account-hack\/\" target=\"_blank\" rel=\"noopener\">AI marketing chatbot maker Salesloft<\/a>, which allowed the hackers to break into a number of their customers\u2019 connected Salesforce instances to steal sensitive data, such as access tokens for other services. Among the victims included insurance giant <a href=\"https:\/\/techcrunch.com\/2025\/08\/18\/allianz-life-data-breach-affects-1-1-million-customers\/\" target=\"_blank\" rel=\"noopener\">Allianz Life<\/a>, Bugcrowd, Cloudflare, <a href=\"https:\/\/techcrunch.com\/2025\/08\/06\/google-says-hackers-stole-its-customers-data-in-a-breach-of-its-salesforce-database\/\" target=\"_blank\" rel=\"noopener\">Google<\/a>, fashion conglomerate <a href=\"https:\/\/techcrunch.com\/2025\/09\/15\/company-that-owns-gucci-balenciaga-other-brands-confirms-hack\/\" target=\"_blank\" rel=\"noopener\">Kering<\/a>, Proofpoint, the airline <a href=\"https:\/\/techcrunch.com\/2025\/07\/02\/qantas-hack-results-in-theft-of-6-million-passengers-personal-data\/\" target=\"_blank\" rel=\"noopener\">Qantas<\/a>, carmaker <a href=\"https:\/\/techcrunch.com\/2025\/09\/22\/automaker-giant-stellantis-says-customers-personal-data-stolen-during-breach\/\" target=\"_blank\" rel=\"noopener\">Stellantis<\/a>, credit bureau <a href=\"https:\/\/techcrunch.com\/2025\/08\/28\/transunion-says-hackers-stole-4-4-million-customers-personal-information\/\" target=\"_blank\" rel=\"noopener\">TransUnion<\/a>, the employee management platform <a href=\"https:\/\/techcrunch.com\/2025\/08\/18\/hr-giant-workday-says-hackers-stole-personal-data-in-recent-breach\/\" target=\"_blank\" rel=\"noopener\">Workday<\/a>, and others.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In the case of the Salesloft breaches, the hacking group Scattered Lapsus$ Hunters, which apparently includes the ShinyHunters gang, <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/shinyhunters-claims-15-billion-salesforce-records-stolen-in-drift-hacks\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">claimed responsibility<\/a>.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Last month, <a href=\"https:\/\/techcrunch.com\/2025\/10\/03\/hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases\/\" target=\"_blank\" rel=\"noopener\">the hackers launched a dedicated website<\/a> to extort the victims of the breaches, where they threatened to release a billion records.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">At the time, Gainsight <a href=\"http:\/\/gainsight.com\/security\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">confirmed<\/a> it was among the victims of the Salesloft-linked breaches, but it\u2019s unclear if this new wave of hacks originated from its earlier compromise.<\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2025\/11\/20\/salesforce-says-some-of-its-customers-data-was-accessed-after-gainsight-breach\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Salesforce said on Wednesday that it\u2019s investigating a breach of \u201ccertain customers\u2019 Salesforce data\u201d that was compromised through apps published by Gainsight, a company that sells a platform for other companies to manage their customers.\u00a0 In a notice published late Wednesday, Salesforce said the hacks involve \u201cGainsight-published applications connected to Salesforce, which are installed and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":206447,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-206446","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/206446","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=206446"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/206446\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/206447"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=206446"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=206446"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=206446"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}