UPDATED 18:26 EST / NOVEMBER 21 2025

SECURITY

Gainsight breach compromises major tech firms’ Salesforce instances

A breach at software provider Gainsight Inc. may have compromised the data of more than 200 Salesforce Inc. customers, including several large tech firms.

The cyberattack was disclosed by Salesforce late Wednesday. Today, a Google LLC cybersecurity researcher told TechCrunch that the search giant “is aware of more than 200 potentially affected Salesforce instances.” Atlassian Corp., Verizon Communications and GitLab Inc. are believed to be among the affected organizations.

Gainsight is owned by Vista Equity Partners, which reportedly paid $1.1 billion for the company in 2020. It sells a cloud platform that organizations can use to track their customer engagement efforts. The platform maintains a chronological database of activities such as client onboarding sessions.

Gainsight’s platform also helps companies collect customer behavior data. It tracks metrics such as the number of users who adopt a newly released application feature. The platform can enrich the data it collects with records from a company’s Salesforce instant, as well as make information available to employees via a Slack bot.

The hackers behind this week’s breach compromised the connection through which Gainsight integrates with Salesforce instances. Before disclosing the incident on Wednesday, Salesforce disabled the connection. It also temporarily removed Gainsight from its AppExchange marketplace of third-party software products.

“There is no indication that this issue resulted from any vulnerability in the Salesforce platform,” Salesforce told customers in a security advisory.

In a memo published today, Gainsight disclosed that it has hired Google’s Mandiant cybersecurity services unit to help it remediate the incident. The company was reportedly compromised during an August breach of another software provider called Salesloft Inc. That incident saw the Scattered Lapsus$ Hunters cybercrime collective breach hundreds of Salesforce environments.

The August cyberattack targeted Salesloft’s Drift chatbot. The tool uses artificial intelligence to answer questions from users who visit a company’s website, as well as estimate how likely they are to make a purchase. Drift can sync the buyer data it collects to Salesforce via an OAuth integration.

Scattered Lapsus$ Hunters compromised Drift by accessing its OAuth credentials. Salesloft users who didn’t connect the chatbot to their Salesforce instances weren’t affected.

Shortly after Salesforce disclosed the Gainsight breach on Wednesday, CrowdStrike Holdings Inc. revealed that a former employee had shared internal data with Scattered Lapsus$ Hunters. The individual, who was dismissed last month, provided the hackers with screenshots of company systems. CrowdStrike stated that the incident is unrelated to the Gainsight breach and didn’t compromise its network or customer data. 

Photo: Unsplash

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.