ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Gainsight cyber incident impacts additional Salesforce customers as investigation expands

A cyberattack involving Gainsight’s Salesforce-connected applications affected more customers than initially identified, prompting wider service restrictions and an ongoing forensic investigation. Gainsight, a U.S.–based customer success platform provider, said Salesforce first supplied a list of three impacted customers on November 20, but subsequent review expanded the number to a larger group. The company notified the affected organizations directly and emphasized that the total remained limited.


Salesforce separately alerted those customers on November 21. In response, Gainsight implemented precautionary restrictions across several products that rely on Salesforce connectivity, temporarily disabling read and write capabilities for Customer Success, Community, Northpass Customer Education, Skilljar, and Staircase. The company stressed that Salesforce removed the Staircase connector out of caution and that no evidence indicated compromise of the application, which operates on segregated infrastructure.


Gong.io, Zendesk, and HubSpot also disabled their connectors to Gainsight applications as safety measures. HubSpot said it found no indication that its systems or customers were affected but kept its Gainsight integration offline while the investigation continued.


Gainsight has been posting frequent updates on its status site and hosting regular customer briefings. The company said it developed interim solutions to help customers manage their Customer Success instances while the Salesforce connected app remained unavailable.


Early findings from the investigation were outlined by Gainsight Chief Executive Chuck Ganapathi, who said the company’s security, support, product, and customer success teams were working alongside Salesforce to analyze the incident. Gainsight also retained Mandiant, the incident response division of Google Cloud, to conduct an independent forensic review.


Indicators of compromise shared through Gainsight’s customer FAQ showed that the first unauthorized access occurred on November 8 through an AT&T IP address associated with reconnaissance activity. Salesforce identified roughly twenty additional suspicious intrusions between November 16 and 23 involving various tools and commercial VPN services such as Mullvad and Surfshark. Gainsight urged customers to block the listed IP addresses at the profile level.


Investigators also noted the use of Salesforce-Multi-Org-Fetcher/1.0, a technique previously observed in other high-profile attacks targeting Salesforce environments. In response, Gainsight rotated multifactor credentials for VPN and critical system access and deployed hardening measures across its infrastructure.


Customers were asked to rotate S3 keys, sign in to Gainsight NXT directly rather than through Salesforce until full restoration of the connected app, reset passwords for NXT users who do not use single sign-on, and re-authorize applications or integrations that rely on user credentials or tokens. Gainsight also recommended adopting preventative measures outlined by Google’s Threat Intelligence Group to mitigate risks associated with threat actors linked to the Shiny Hunter, Scattered Spider, and Lapsus$ collective.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543