By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Gulf PressGulf Press
  • Home
  • Gulf News
  • World
  • Business
  • Technology
  • Sports
  • Lifestyle
Search
Countries
More Topics
  • Health
  • Entertainment
Site Links
  • Customize Interests
  • Bookmarks
  • Newsletter
  • Terms
  • Press Release
  • Advertise
  • Contact
© 2023 Gulf Press. All Rights Reserved.
Reading: Google says hackers stole data from 200 companies following Gainsight breach
Share
Notification Show More
Latest News
Oman, USA discuss ways to maximise benefits of Free Trade Agreement
Gulf
Fantasy futsal: Azerbaijan impress indoors as global game reach soars
World
Minister of State for Interior Affairs meets Ambassador of UK to Qatar.
Gulf
Firmino stars as Al Sadd clinch Super Shield
Sports
Katara seminar highlights AI role in developing healthcare sector
Gulf
Aa
Gulf PressGulf Press
Aa
  • Gulf News
  • World
  • Business
  • Entertainment
  • Lifestyle
  • Sports
Search
  • Home
  • Gulf
  • Business
  • More News
    • World
    • Technology
    • Lifestyle
    • Entertainment
    • Sports
Have an existing account? Sign In
Follow US
  • Terms
  • Press Release
  • Advertise
  • Contact
© 2023 Gulf Press. All Rights Reserved.
Gulf Press > Technology > Google says hackers stole data from 200 companies following Gainsight breach
Technology

Google says hackers stole data from 200 companies following Gainsight breach

News Room
Last updated: 2025/11/24 at 6:12 PM
News Room
Share
6 Min Read
SHARE

Google has confirmed a large-scale data breach affecting over 200 companies using Salesforce, resulting from a sophisticated supply chain attack. The incident, disclosed by Salesforce on Thursday, stems from compromised access via applications connected to the platform, specifically those provided by customer support company Gainsight. Security researchers are investigating the extent of the damage and potential exposure of sensitive customer data.

Contents
How the Breach Occurred: A Look at the Attack ChainCompany Responses and InvestigationsExtortion Threats and the Group’s Motives

Significant Salesforce Data Breach Impacts Hundreds of Companies

The breach centers around data stolen through applications published by Gainsight, a customer success platform popular with businesses of all sizes. According to a statement from Austin Larsen, Principal Threat Analyst at Google’s Threat Intelligence Group, the company is currently aware of more than 200 potentially affected Salesforce instances. The notorious hacking group, Scattered Lapsus$ Hunters—which incorporates the activities of ShinyHunters—has claimed responsibility for the attack.

Scattered Lapsus$ Hunters publicly stated their involvement via a Telegram channel, and have specifically named several organizations as victims, including Atlassian, CrowdStrike, Docusign, F5, GitLab, LinkedIn, Malwarebytes, SonicWall, Thomson Reuters, and Verizon. The group is known for its aggressive tactics, combining social engineering with technical exploits to gain access to systems and data.

How the Breach Occurred: A Look at the Attack Chain

The hackers reportedly gained access through a previous campaign targeting customers of Salesloft, another platform offering AI-powered marketing tools. According to ShinyHunters representatives in an online chat with TechCrunch, they initially stole authentication tokens from Salesloft customers. These tokens allowed them to access linked Salesforce instances and exfiltrate data. Gainsight was confirmed as a victim of the initial Salesloft breach, leaving it as a potential entry point in this wider attack.

Salesforce maintains that the breach did not originate from a vulnerability within its own platform. “There is no indication that this issue resulted from any vulnerability in the Salesforce platform,” the company stated, distancing itself from the security failures of its customers’ integrated applications. However, the incident highlights the inherent risks of connecting third-party applications to sensitive data stores.

Company Responses and Investigations

Several companies named by the hacking group have issued statements. CrowdStrike spokesperson Kevin Benacci confirmed the company was not affected by the Gainsight issue and that customer data remained secure. They also disclosed the termination of a “suspicious insider” allegedly involved in passing information to the hackers. Verizon acknowledged the claim but stated it was unsubstantiated, while Malwarebytes confirmed it was actively investigating the matter.

Docusign stated that a log analysis had, so far, revealed no compromise of their data. Nevertheless, the company proactively terminated all Gainsight integrations and contained related data flows as a precautionary measure. A Thomson Reuters spokesperson indicated that the company is also actively investigating the situation. At the time of publication, several other companies mentioned by the group had not responded to requests for comment.

Gainsight has been providing updates on its incident page, and is now working with Google’s Mandiant unit to investigate. The company affirmed the breach originated from external connections to the Salesforce platform, not from a weakness within Salesforce itself. Forensic analysis is ongoing.

Extortion Threats and the Group’s Motives

Scattered Lapsus$ Hunters plans to launch a dedicated website next week to extort the victims of this campaign – a tactic previously employed following the Salesloft incident. This suggests a financially motivated operation, with the hackers seeking ransom payments in exchange for not publishing stolen data. This group is known to be a collective of several cybercriminal gangs, utilizing social engineering to infiltrate systems.

The group’s past targets have included major organizations like MGM Resorts, Coinbase, and DoorDash, demonstrating a pattern of targeting high-profile companies with valuable data. The incident underscores the growing threat of supply chain attacks, where hackers exploit vulnerabilities in third-party vendors to gain access to a larger network of targets. This incident is a stark reminder of the importance of robust data security measures, especially when integrating third-party applications.

The full scope of the impacted Salesforce data and the specific nature of the information stolen are still being determined. Salesforce has temporarily revoked active access tokens for Gainsight-connected apps as a precaution and is notifying affected customers. The larger ramifications for cloud security, and the need for stricter vendor risk management, are likely to be discussed in the coming weeks.

Looking ahead, the focus will be on the findings of the ongoing forensic investigations by Gainsight and Mandiant. Companies utilizing Gainsight and similar applications should review their security protocols and access controls to mitigate potential risks. The launch of the extortion website by Scattered Lapsus$ Hunters will also be a key event to monitor, as it may provide further details about the stolen data and the group’s demands.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
I have read and agree to the terms & conditions
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
News Room November 24, 2025
Share this Article
Facebook Twitter Copy Link Print
Previous Article Arab national held for modifying a vehicle taken on rent, attempting to sell in Oman
Next Article Byju’s founder liable for over $1 billion default judgment, plans appeal
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

235.3k Followers Like
69.1k Followers Follow
56.4k Followers Follow
136k Subscribers Subscribe
- Advertisement -
Ad imageAd image

Latest News

Oman, USA discuss ways to maximise benefits of Free Trade Agreement
Gulf January 25, 2026
Fantasy futsal: Azerbaijan impress indoors as global game reach soars
World January 25, 2026
Minister of State for Interior Affairs meets Ambassador of UK to Qatar.
Gulf January 25, 2026
Firmino stars as Al Sadd clinch Super Shield
Sports January 25, 2026

You Might also Like

Technology

Tech CEOs boast and bicker about AI at Davos

January 25, 2026
Technology

Gmail is having issues with spam and misclassification

January 25, 2026
Technology

Adobe Acrobat now lets you edit files using prompts, generate podcast summaries

January 24, 2026
Technology

TechCrunch Disrupt 2026 tickets now on sale: Lowest rates all year 

January 24, 2026
Technology

OpenAI aims to ship its first device in 2026, and it could be earbuds

January 24, 2026
Technology

YouTube will soon let creators make Shorts with their own AI likeness

January 24, 2026
Technology

OpenAI’s former sales leader joins VC firm Acrew: OpenAI taught her where startups can build a ‘moat’ 

January 24, 2026
Technology

We’re not nostalgic for 2016 — we’re nostalgic for the internet before all the slop

January 24, 2026
//

Gulf Press is your one-stop website for the latest news and updates about Arabian Gulf and the world, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of ue
  • Advertise
  • Contact

How Topics

  • Gulf News
  • International
  • Business
  • Lifestyle

Sign Up for Our Newsletter

Subscribe to our newsletter to get our latest news instantly!

I have read and agree to the terms & conditions
Gulf PressGulf Press
Follow US

© 2023 Gulf Press. All Rights Reserved.

Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

I have read and agree to the terms & conditions
Zero spam, Unsubscribe at any time.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?