22/11/2025
Salesforce has sounded the alarm after detecting unusual and potentially risky activity involving Gainsight-published applications connected to its platform.
According to an advisory from the company, the investigation suggests that this activity may have allowed unauthorized access to some customers’ Salesforce data through the affected app connections. In response, Salesforce has revoked all active access and refresh tokens tied to Gainsight-published apps and has temporarily removed those apps from the AppExchange while the review continues.
Although Salesforce has not disclosed how many customers were affected, it confirmed that all impacted organizations have been notified. Importantly, the company emphasized that there’s no evidence of any vulnerability in the Salesforce platform itself—the issue appears to stem from the app’s external integrations.
Gainsight has also taken precautionary steps: the app has been pulled from the HubSpot Marketplace, and Zendesk connector access has been disabled. These actions may temporarily disrupt OAuth connections for customers, though Gainsight noted that no suspicious behavior has been detected in HubSpot so far.
Adding to the concern, Austin Larsen of Google’s Threat Intelligence Group described the incident as part of an “emerging campaign” targeting Gainsight-published Salesforce apps, where attackers compromise third-party OAuth tokens to gain unauthorized access. The activity is believed to be linked to the ShinyHunters (UNC6240) threat group—the same actors behind similar attacks on Salesloft Drift instances earlier this August.
ShinyHunters has claimed responsibility for the campaign, telling DataBreaches.net that the Salesloft and Gainsight intrusions enabled them to steal data from nearly 1,000 organizations.
How ETSPL & Consult Innservices Help Organizations Build Stronger Cyber Resilience
Incidents like the Gainsight–Salesforce compromise highlight a critical truth: third-party integrations are becoming one of the weakest links in enterprise security. This is exactly where EBC TECH SERV PVT LTD (ETSPL) and Consult Innservices play a transformative role—by helping organizations build both pre-breach and post-breach cybersecurity architectures that match their operational needs, budgets, and risk appetite.
Pre-Breach: Strengthening Defenses Before an Attack
ETSPL & Consult Innservices design budget-aligned, business-focused security architectures that minimize exposure to risks such as OAuth token theft, credential misuse, and compromised third-party apps. Their pre-breach services include:
Threat and risk assessments
Identity & Access Management (IAM) and MFA enforcement
Zero Trust & cloud security architecture
SIEM & log monitoring
Endpoint/EDR deployment
Network and app security reviews
Vulnerability management
Security awareness & phishing training
Backup and business continuity planning
These preventive layers help organizations detect unusual activity early—often before attackers gain meaningful access.
Post-Breach: Rapid Response + Recovery
If an incident does occur, ETSPL & Consult Innservices provide structured, SLA-driven support to contain, investigate, and remediate the breach:
Digital forensics & incident response
Compromise assessment
Account/token reset & containment actions
Threat hunting to eliminate persistence
Compliance & notification support
Recovery & monitoring
Post-incident hardening to prevent recurrence
Their approach ensures faster containment, minimal downtime, and restored confidence for both the business and its customers.
Flexible, Budget-Friendly Cybersecurity Packages
To ensure every organization—from small startups to large enterprises—can enhance their security posture, ETSPL & Consult Innservices offer three scalable security programs:
Bronze (Essentials): Affordable protection for SMBs
Silver (Growth): Enhanced defense for mid-size organizations
Gold (Enterprise): Advanced, 24/7 monitoring and incident readiness
Each package is designed to deliver maximum protection without unnecessary cost.
In a landscape where threat actors increasingly target trusted integrations and third-party ecosystems, ETSPL & Consult Innservices provide the proactive and reactive cybersecurity frameworks organizations need to stay secure, compliant, and resilient—before and after a breach.