North America
Gainsight
Google has confirmed that hackers stole data stored by Salesforce belonging to more than 200 companies in the large-scale Salesforce-Gainsight supply chain breach.
On November 19, Salesforce announced it was investigating a breach affecting some customers whose data was exposed through apps published by Gainsight, a customer success platform. Google's Threat Intelligence Group has since stated it is aware of more than 200 potentially impacted Salesforce instances. Shortly after Salesforce disclosed the issue, the hacking group Scattered Lapsus$ Hunters claimed responsibility for the attack.
Salesforce said there is no evidence to suggest the breach resulted from a vulnerability in its own platform. Instead, the activity appears linked to Gainsight's external connection to Salesforce. To protect customers, Salesforce has disabled the integration and revoked all active and refresh tokens associated with Gainsight-published apps.
How it could affect your business
This incident shows attackers no longer need to breach systems directly — they can infiltrate through trusted integrations and connected apps. Businesses should map all third-party connections, enforce strict token and API permission controls and continuously audit external tools' access points to prevent hidden backdoors.