Salesforce Customers Targeted in New Data โฃBreach Followingโ Gainsight Incident
SAN FRANCISCO,โฃ CA โ- November โฃ1, 2025 – Salesforce customers are facing โฃpotential data exposure after โa hacking group claimed to have stolenโฃ data from nearly a thousand companies through a breachโข linked to Gainsight, a customer success โคplatform integrated with Salesforce. The hackersโ are threatening to โpublish theโ stolen data on a new website if ransomsโ are not paid – a common tactic employed by financially-motivated cybercriminals.
the breach appears connected to a series of incidents originatingโค with anโ August compromise โof AI marketing chatbot maker Salesloft, which allowed attackers to accessโข connected โSalesforce instances. This latest development underscores โคthe โgrowing risk of supply chain attacks and the vulnerability โof customer data stored within widely-used platformsโฃ like Salesforce.Gainsight previouslyโข confirmed it was among the victims ofโ the Salesloft-linked breaches, though it remains unclear ifโข this new waveโข originated from โคthe earlier compromise.
According to a reportโ by DataBreaches.net, the hacking group warnedโฃ they “don’t negotiate with them, they will create a new website to advertise the stolen data.” The hackers claim to have stolen โขdata from close to a thousand companies and stated, “The next [data leak site] will contain the data of the Salesloft and GainSight campaigns.”
This incident is part of a largerโ pattern of attacks targeting Salesforce customers. previous victims of similar breaches include insurance giant Allianz Life, Bugcrowd, Cloudflare, Google, fashion conglomerate Kering, Proofpoint, airline Qantas, carmaker Stellantis,โค credit bureau TransUnion, and employee management platformโค Workday.
The hacking group,identified as Scattered Lapsus$ Hunters -โค which โreportedly includes the ShinyHuntersโ gang – claimed dutyโ for the Salesloft breaches and previously launched a dedicated website to โextort victims,threatening to release aโ billion records. Gainsight has acknowledged โthe earlier breaches but has not yet commented โฃon this latest claim.