
Salesforce said it revoked refresh tokens tied to applications published by Gainsight after identifying unusual activity that enabled unauthorized access to customer data through the apps’ external connections. The action was taken Thursday morning as the cloud software provider investigated a new wave of data theft attempts targeting users of its customer relationship management platform.
The company stated that the activity originated from Gainsight-developed applications that customers installed and managed directly, and not from any vulnerability within Salesforce’s own systems. The investigation found that the malicious behavior involved the apps’ external link to Salesforce rather than the core CRM platform.
Salesforce said it immediately disabled all active access and refresh tokens associated with the Gainsight-published applications and temporarily removed the apps from the AppExchange. Impacted customers were notified, and those needing support were directed to Salesforce’s help team.
The incident mirrored a series of attacks in August 2025 involving Salesloft’s Drift AI integration, when the Scattered Lapsus$ Hunters extortion group used stolen OAuth tokens to infiltrate numerous Salesforce environments. That campaign led to the theft of 1.5 billion Salesforce records from roughly 760 companies, including major technology and cybersecurity firms.
ShinyHunters, the extortion group that previously claimed responsibility for the Salesloft intrusions, stated that it recently accessed an additional 285 Salesforce instances by abusing secrets taken in the earlier Drift breach. Gainsight had already confirmed it was compromised through stolen OAuth tokens linked to Salesloft’s Drift system, allowing attackers to obtain business contact information such as names, corporate email addresses, phone numbers, regional details, licensing data, and support case content.
Gainsight did not provide additional comment on the latest attacks involving its applications.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543