Salesforce customers face second third-party incident this year with Gainsight breach

Customers impacted in the Gainsight breach have been contacted by Salesforce

Salesforce logo pictured at the 8th China International Import Expo in Shanghai, China.
(Image credit: Getty Images)

Salesforce has launched an investigation into a spate of customer data theft incidents following a breach at a third-party application provider.

In a statement on Thursday 20 November, the CRM giant revealed it had revoked access and refresh tokens for Gainsight-published applications as part of its response to the breach.

Gainsight is a software as a service (SaaS) provider specializing in customer success and product experience, available to Salesforce customers via the company’s App Exchange platform.

Image

Stay ahead of cyber risks with the NordStellar threat intelligence platform.

<p><a href="https://go.nordstellar.net/aff_c?offer_id=927&aff_id=3013" target="_blank">Black Friday offer! Illuminate the dark web with the code BLACKFRIDAY20 and get 20% off

“Salesforce has identified unusual activity involving Gainsight-published applications connected to Salesforce, which are installed and managed directly by customers,” the company said in an advisory.

Salesforce noted that a preliminary investigation suggests the breach could have enabled “unauthorized access to certain customers’ Salesforce data” through Gainsight connections.

“Upon detecting the activity, Salesforce revoked all active access and refresh tokens associated with Gainsight-published applications connected to Salesforce and temporarily removed those applications from the AppExchange while our investigation continues,” the advisory added.

Exact details on the scope of the incident and those affected are yet to be revealed. However, Salesforce confirmed that affected customers have been notified.

Gainsight the latest third-party incident for Salesforce

The Gainsight incident marks the latest third-party application breach for Salesforce in recent months.

Earlier this year, the Salesloft Drift attack impacted hundreds of companies including Google, Zscaler, Cloudflare, and Palo Alto Networks.

Hackers gained access to sensitive customer data through compromised OAuth tokens associated with the third-party application.

Brian Soby, CTO and co-founder at AppOmni, said the scale of Gainsight integrations means this latest incident could have equally wide-reaching implications for an array of businesses.

“Gainsight is widely deployed and tightly connected to Salesforce, Slack, Google, Microsoft, and numerous other SaaS environments,” he said. “Because of that footprint, customers now have to quickly identify every location where Gainsight was integrated.”

Soby added that the Gainsight incident once again highlights “persistent weaknesses” in SaaS supply chain security practices.

“The attack closely mirrors the earlier Drift breach, which also targeted Salesforce, Google Workspace, and other widely used SaaS platforms,” he told ITPro.

“The scale of the Gainsight compromise underscores that many organizations did not apply the lessons they should have learned from Drift, leaving large portions of their SaaS supply chain exposed.”

Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.

MORE FROM ITPRO

Ross Kelly
News and Analysis Editor

Ross Kelly is ITPro's News & Analysis Editor, responsible for leading the brand's news output and in-depth reporting on the latest stories from across the business technology landscape. Ross was previously a Staff Writer, during which time he developed a keen interest in cyber security, business leadership, and emerging technologies.

He graduated from Edinburgh Napier University in 2016 with a BA (Hons) in Journalism, and joined ITPro in 2022 after four years working in technology conference research.

For news pitches, you can contact Ross at ross.kelly@futurenet.com, or on Twitter and LinkedIn.