Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

ShinyHunters Claims Data Theft from 200+ Companies via Salesforce Gainsight Breach

A sophisticated supply chain attack has reportedly compromised data across hundreds of organizations, linking the breach to a critical integration between customer success platform Gainsight and CRM giant Salesforce.

A sophisticated supply chain attack has reportedly compromised data across hundreds of organizations, linking the breach to a critical integration between customer success platform Gainsight and CRM giant Salesforce.

The notorious hacking collective ShinyHunters is claiming responsibility for the intrusion, which allegedly affects over 200 companies. The attack vector did not rely on breaking into Salesforce directly but instead on exploiting the trusted connection established through third-party applications.

On November 20, 2025, Salesforce took emergency action to contain the threat. The company officially disabled the connection between Gainsight-published applications and the Salesforce ecosystem after detecting “unusual activity.”

According to a statement from Salesforce, their investigation suggests that the activity facilitated unauthorized access to customer data, specifically through the app’s external connection.

The mechanics of this campaign highlight a growing trend in modern cyber warfare: targeting the “keys” rather than the “locks.”

The Google Threat Intelligence Group (GTIG), including researchers from Mandiant, identified the threat actors as affiliates of ShinyHunters. These adversaries compromised third-party OAuth tokens.

In the SaaS environment, OAuth tokens function like digital permissions slips, allowing apps like Gainsight to talk to Salesforce without requiring a user to log in every time.

The notorious hacking collective ShinyHunters is claiming responsibility for the intrusion, which allegedly affects over 200 companies.
Vanessa Ray · Thehackingpost

By stealing these tokens, the attackers could potentially bypass multi-factor authentication and standard login defenses, masquerading as the trusted application to exfiltrate sensitive corporate data. This method allows threat actors to move laterally within cloud environments while remaining undetected by traditional perimeter security.

While the scope of the data loss is potentially massive, Salesforce has been clear in its distinction regarding where the fault lies. The company emphasized that there is “no indication that this issue resulted from any vulnerability in the Salesforce platform.” Instead, the breach is strictly related to the external connection and the management of credentials for the Gainsight integration.

Currently, customers are unable to connect their Gainsight-published applications to Salesforce until further notice. Both Salesforce and Mandiant are actively notifying organizations that show signs of compromise.

This incident mirrors similar campaigns observed recently, such as attacks targeting Salesloft Drift , suggesting a concerted effort by threat groups to audit and exploit SaaS ecosystems where third-party permissions are often granted and forgotten.

Urgent Actions for SaaS Administrators

This incident serves as a critical wake-up call for organizations relying on interconnected SaaS platforms. Security teams are urged to immediately treat this as a signal to audit their entire cloud environment.

The primary recommendation is to review all connected apps within Salesforce instances and revoke OAuth tokens for any integration that is unused, suspicious, or related to the affected Gainsight applications.

Advertisement

Organizations using Gainsight integrations should monitor for official communications from both vendors, Salesforce and Gainsight .

However, proactive defense is required. If any anomalous activity is detected from an integration, administrators should rotate credentials immediately and assume a potential compromise.

As threat actors increasingly pivot toward identity-based attacks and token theft, the maintenance of third-party permissions has become just as vital as patching software vulnerabilities.

Here is the table of Indicators of Compromise (IoCs) associated with the ShinyHunters campaign targeting Salesforce and Gainsight integrations.

IOC TypeValueFirst Seen (UTC)Last Seen (UTC)Observed ActivityIP Address104.3.11[.]12025-11-08 13:11:292025-11-08 13:15:23AT&T IP; reconnaissance and unauthorized access. ​IP Address198.54.135[.]1482025-11-16 21:48:032025-11-16 21:48:03Mullvad VPN proxy IP; reconnaissance and unauthorized access. ​IP Address198.54.135[.]1972025-11-16 22:00:562025-11-16 22:06:57Mullvad VPN proxy IP; reconnaissance and unauthorized access. ​IP Address198.54.135[.]2052025-11-18 10:43:552025-11-18 12:09:35Mullvad VPN proxy IP; reconnaissance and unauthorized access. obsi​IP Address146.70.171[.]2162025-11-18 20:21:482025-11-18 20:50:13Mullvad VPN proxy IP; reconnaissance and unauthorized access. ​IP Address169.150.203[.]2452025-11-18 20:54:022025-11-18 23:04:12Surfshark VPN proxy IP; reconnaissance and unauthorized access. ​IP Address172.113.237[.]482025-11-18 21:23:292025-11-18 21:51:32NSocks VPN proxy IP; reconnaissance and unauthorized access. ​IP Address45.149.173[.]2272025-11-18 22:05:152025-11-18 22:05:18Surfshark VPN proxy IP; reconnaissance and unauthorized access. ​IP Address135.134.96[.]762025-11-19 08:26:182025-11-19 10:30:37IProxyShop VPN proxy IP; reconnaissance and unauthorized access. ​IP Address65.195.111[.]212025-11-19 10:57:372025-11-19 10:59:19IProxyShop VPN proxy IP; reconnaissance and unauthorized access. ​IP Address65.195.105[.]812025-11-19 11:17:512025-11-19 11:48:07Nexx VPN proxy IP; reconnaissance and unauthorized access. ​IP Address65.195.105[.]1532025-11-19 12:23:172025-11-19 12:23:35ProxySeller VPN proxy IP; reconnaissance and unauthorized access. ​IP Address45.66.35[.]352025-11-19 12:47:432025-11-19 12:47:45Tor VPN proxy IP; reconnaissance and unauthorized access. ​IP Address146.70.174[.]692025-11-19 12:47:492025-11-19 12:47:49Proton VPN proxy IP; reconnaissance and unauthorized access. ​IP Address82.163.174[.]832025-11-19 14:30:362025-11-19 22:26:46ProxySeller VPN proxy IP; reconnaissance and unauthorized access. ​IP Address3.239.45[.]432025-10-23 00:17:222025-10-23 00:45:36AWS IP; reconnaissance against customers with compromised Gainsight access token. ​User Agentpython-requests/2.28[.]12025-11-08 13:11:192025-11-08 13:15:01Not an expected user agent string used by Gainsight connected app; use in conjunction with other IOCs shared. ​User Agentpython-requests/2.32[.]32025-11-16 21:48:032025-11-16 21:48:03Not an expected user agent string used by Gainsight connected app; use in conjunction with other IOCs shared. ​User Agentpython/3.11 aio 00:00:002025-10-23 00:01:00Not an expected user agent string used by Gainsight connected app; use in conjunction with other IOCs shared. ​User AgentSalesforce-Multi-Org-Fetcher/1.02025-11-18 22:05:132025-11-19 22:24:01Leveraged by threat actor for unauthorized access; also observed in Salesloft Drift activity. ​ Follow us on Google News , LinkedIn , and X for daily cybersecurity updates. Contact us to feature your stories.

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories