By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Gulf PressGulf Press
  • Gulf News
    • Saudi Arabia
    • UAE
    • Oman
    • Kuwait
    • Qatar
    • Bahrain
  • Business
  • Technology
  • Real Estate
  • Sport
  • Travel
  • Lifestyle
  • Rankings
  • Explained
  • Opinion
Search
Countries
More Topics
Site Links
  • Newsletter
  • Terms
  • About Us
  • Advertise with us
  • Contact Us
© 2023 Gulf Press. All Rights Reserved.
Reading: Google says hackers stole data from 200 companies following Gainsight breach
Share
Notification Show More
Latest News
Taif Governor Inspects Historic District, Vows Heritage Preservation
Saudi Arabia
National Committee Reviews Government Policy for Sustainable Endowments and Zakat Funds Wednesday
UAE
Are Rising Living Costs Changing Life in Gulf Countries?
Are Rising Living Costs Changing Life in Gulf Countries?
Opinion
Saudi Arabia National Team Fixtures 2026 Match Schedule Results and FIFA World Cup Preparation
Saudi Arabia National Team Fixtures 2026 Match Schedule Results and FIFA World Cup Preparation
Sport
Families Swap Late Nights for Discipline Ahead of School Reopening
Saudi Arabia
Aa
Gulf PressGulf Press
Aa
  • Gulf News
  • Business
  • Technology
  • Real Estate
  • Sport
  • Travel
  • Lifestyle
  • Rankings
  • Explained
  • Opinion
Search
  • Gulf News
    • Saudi Arabia
    • UAE
    • Oman
    • Kuwait
    • Qatar
    • Bahrain
  • Business
  • Technology
  • Real Estate
  • Sport
  • Travel
  • Lifestyle
  • Rankings
  • Explained
  • Opinion
Have an existing account? Sign In
Follow US
  • Terms
  • About Us
  • Advertise with us
  • Contact Us
© 2023 Gulf Press. All Rights Reserved.
Gulf Press > Technology > Google says hackers stole data from 200 companies following Gainsight breach
Technology

Google says hackers stole data from 200 companies following Gainsight breach

News Room
Last updated: 2025/11/24 at 6:12 PM
News Room
Share
6 Min Read
SHARE

Google has confirmed a large-scale data breach affecting over 200 companies using Salesforce, resulting from a sophisticated supply chain attack. The incident, disclosed by Salesforce on Thursday, stems from compromised access via applications connected to the platform, specifically those provided by customer support company Gainsight. Security researchers are investigating the extent of the damage and potential exposure of sensitive customer data.

Contents
How the Breach Occurred: A Look at the Attack ChainCompany Responses and InvestigationsExtortion Threats and the Group’s Motives

Significant Salesforce Data Breach Impacts Hundreds of Companies

The breach centers around data stolen through applications published by Gainsight, a customer success platform popular with businesses of all sizes. According to a statement from Austin Larsen, Principal Threat Analyst at Google’s Threat Intelligence Group, the company is currently aware of more than 200 potentially affected Salesforce instances. The notorious hacking group, Scattered Lapsus$ Hunters—which incorporates the activities of ShinyHunters—has claimed responsibility for the attack.

Scattered Lapsus$ Hunters publicly stated their involvement via a Telegram channel, and have specifically named several organizations as victims, including Atlassian, CrowdStrike, Docusign, F5, GitLab, LinkedIn, Malwarebytes, SonicWall, Thomson Reuters, and Verizon. The group is known for its aggressive tactics, combining social engineering with technical exploits to gain access to systems and data.

How the Breach Occurred: A Look at the Attack Chain

The hackers reportedly gained access through a previous campaign targeting customers of Salesloft, another platform offering AI-powered marketing tools. According to ShinyHunters representatives in an online chat with TechCrunch, they initially stole authentication tokens from Salesloft customers. These tokens allowed them to access linked Salesforce instances and exfiltrate data. Gainsight was confirmed as a victim of the initial Salesloft breach, leaving it as a potential entry point in this wider attack.

Salesforce maintains that the breach did not originate from a vulnerability within its own platform. “There is no indication that this issue resulted from any vulnerability in the Salesforce platform,” the company stated, distancing itself from the security failures of its customers’ integrated applications. However, the incident highlights the inherent risks of connecting third-party applications to sensitive data stores.

Company Responses and Investigations

Several companies named by the hacking group have issued statements. CrowdStrike spokesperson Kevin Benacci confirmed the company was not affected by the Gainsight issue and that customer data remained secure. They also disclosed the termination of a “suspicious insider” allegedly involved in passing information to the hackers. Verizon acknowledged the claim but stated it was unsubstantiated, while Malwarebytes confirmed it was actively investigating the matter.

Docusign stated that a log analysis had, so far, revealed no compromise of their data. Nevertheless, the company proactively terminated all Gainsight integrations and contained related data flows as a precautionary measure. A Thomson Reuters spokesperson indicated that the company is also actively investigating the situation. At the time of publication, several other companies mentioned by the group had not responded to requests for comment.

Gainsight has been providing updates on its incident page, and is now working with Google’s Mandiant unit to investigate. The company affirmed the breach originated from external connections to the Salesforce platform, not from a weakness within Salesforce itself. Forensic analysis is ongoing.

Extortion Threats and the Group’s Motives

Scattered Lapsus$ Hunters plans to launch a dedicated website next week to extort the victims of this campaign – a tactic previously employed following the Salesloft incident. This suggests a financially motivated operation, with the hackers seeking ransom payments in exchange for not publishing stolen data. This group is known to be a collective of several cybercriminal gangs, utilizing social engineering to infiltrate systems.

The group’s past targets have included major organizations like MGM Resorts, Coinbase, and DoorDash, demonstrating a pattern of targeting high-profile companies with valuable data. The incident underscores the growing threat of supply chain attacks, where hackers exploit vulnerabilities in third-party vendors to gain access to a larger network of targets. This incident is a stark reminder of the importance of robust data security measures, especially when integrating third-party applications.

The full scope of the impacted Salesforce data and the specific nature of the information stolen are still being determined. Salesforce has temporarily revoked active access tokens for Gainsight-connected apps as a precaution and is notifying affected customers. The larger ramifications for cloud security, and the need for stricter vendor risk management, are likely to be discussed in the coming weeks.

Looking ahead, the focus will be on the findings of the ongoing forensic investigations by Gainsight and Mandiant. Companies utilizing Gainsight and similar applications should review their security protocols and access controls to mitigate potential risks. The launch of the extortion website by Scattered Lapsus$ Hunters will also be a key event to monitor, as it may provide further details about the stolen data and the group’s demands.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
[mc4wp_form]
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
News Room November 24, 2025
Share this Article
Facebook Twitter Copy Link Print
Previous Article Arab national held for modifying a vehicle taken on rent, attempting to sell in Oman
Next Article Byju’s founder liable for over $1 billion default judgment, plans appeal
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

235.3k Followers Like
69.1k Followers Follow
56.4k Followers Follow
136k Subscribers Subscribe
- Advertisement -
Ad imageAd image

Latest News

Taif Governor Inspects Historic District, Vows Heritage Preservation
Saudi Arabia June 5, 2026
National Committee Reviews Government Policy for Sustainable Endowments and Zakat Funds Wednesday
UAE June 5, 2026
Are Rising Living Costs Changing Life in Gulf Countries?
Are Rising Living Costs Changing Life in Gulf Countries?
Opinion June 4, 2026
Saudi Arabia National Team Fixtures 2026 Match Schedule Results and FIFA World Cup Preparation
Saudi Arabia National Team Fixtures 2026 Match Schedule Results and FIFA World Cup Preparation
Sport June 4, 2026

You Might also Like

Best Smartphones in 2026 Ranked by Performance
Technology

Best Smartphones in 2026 Ranked by Performance

June 4, 2026
Technology

MITHRA Metals advances strategic nickel laterite initiative in Ethiopia

June 4, 2026
Best AI Tools for SEO and Digital Marketing
Technology

Best AI Tools for SEO and Digital Marketing

June 4, 2026
How to Use ChatGPT for Business Growth in 2026
Technology

How to Use ChatGPT for Business Growth in 2026

June 3, 2026
Best AI Apps for Android and iPhone in 2026
Technology

Best AI Apps for Android and iPhone in 2026

June 2, 2026
Top AI Tools for Students in 2026
Technology

Top AI Tools for Students in 2026

June 2, 2026
Best AI Writing Tools for Content Creators in 2026
Technology

Best AI Writing Tools for Content Creators in 2026

June 1, 2026
Best AI Video Generator Tools in 2026
Technology

Best AI Video Generator Tools in 2026

June 1, 2026
//

GulfPress is a modern Gulf media platform delivering trusted news, business insights, technology updates, real estate trends, travel stories, explainers, and rankings from across the GCC and the Middle East.

Quick Link

  • About Us
  • Editorial Policy
  • Corrections Policy
  • Advertise with us
  • Contact Us
  • Privacy Policy
  • Terms of use

How Topics

  • Gulf News
  • Business
  • Lifestyle

Sign Up for Our Newsletter

Subscribe to our newsletter to get our latest news instantly!

[mc4wp_form]

Gulf PressGulf Press
Follow US

© 2023 Gulf Press. All Rights Reserved.

Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

[mc4wp_form]
Zero spam, Unsubscribe at any time.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?