Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Gainsight Salesforce Breach 2025: How 285 Long-Lived OAuth…
Breach analysis Incident: 19 Nov 2025

Gainsight Salesforce Breach 2025: How 285 Long-Lived OAuth Tokens Opened Customers’ CRM Data

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 10 min read
Category: NHI
On this page

On 19 November 2025 Salesforce said it had "identified unusual activity involving Gainsight-published applications connected to Salesforce" and revoked every access and refresh token issued to those apps. Gainsight's customer success platform connects to customers' Salesforce orgs through OAuth, and someone had been calling Salesforce APIs with those tokens from infrastructure that was not Gainsight's. Google's Threat Intelligence Group said it was aware of more than 200 potentially affected Salesforce instances and linked the activity to ShinyHunters (UNC6240). Gainsight's CEO said the company knew of "only a handful" of customers whose data was affected. Gainsight's later account, based on Mandiant and CrowdStrike investigations, says the attacker held 285 OAuth tokens, the newest created in August 2023 and the oldest in October 2017, and used the valid ones between 16 and 19 November 2025. How the tokens were first stolen has not been established.

Key takeaways

  • Salesforce detected API calls using Gainsight's connected-app OAuth tokens from non-Gainsight infrastructure, revoked all tokens for Gainsight-published apps on 19 November 2025 and pulled the apps from AppExchange.
  • According to Gainsight, Mandiant received a file of 285 Salesforce OAuth tokens from the attacker on 20 November; the attacker had tested about 250 of them on 22 October and used the valid ones from 16 to 19 November.
  • Google Threat Intelligence Group counted more than 200 potentially affected Salesforce instances; ShinyHunters claimed 285. Gainsight said it knew of only a handful of customers with data affected.
  • The tokens were between two and eight years old. Gainsight says investigators found no evidence they came from its systems within its one-year log window, so their original source is unknown.
  • The identity lesson: an OAuth refresh token that never expires is a permanent key to a customer's tenant, and Gainsight's own conclusion was that its tokens "were allowed to live too long."

At a glance

OrganisationsGainsight (customer success platform) and Salesforce customers that connected Gainsight-published applications to their orgs
WhenBulk token testing about 22 October 2025; API abuse 16 to 19 November 2025; Salesforce advisory 19 November 2025; Gainsight investigation summary 2 January 2026
AttackerLikely ShinyHunters (UNC6240), according to Google Threat Intelligence Group; the group later claimed responsibility to The Register
Entry pointStolen OAuth tokens issued to the Gainsight connected app for Salesforce; how they were originally obtained is unknown
Identities abusedSalesforce OAuth access and refresh tokens belonging to Gainsight's integration, 285 in the attacker's file
ImpactUnauthorised API access to customer Salesforce data; more than 200 instances potentially affected per Google, a handful of customers with data affected per Gainsight
CategoryNHI. Incident class: confirmed NHI breach (stolen SaaS integration OAuth tokens used against customer tenants)

What happened

Gainsight sells customer success software that pulls account data from a company's Salesforce org. Like most SaaS-to-SaaS integrations, it does this through a Salesforce connected app: each customer authorises the app once, and Gainsight holds an OAuth refresh token that lets it keep calling Salesforce APIs on the customer's behalf without a person signing in again. In 2025 these integration tokens were the main target of a campaign that had already hit customers of Salesloft Drift.

Salesforce raised the alarm late on 19 November 2025, according to The Register. Its advisory said the activity "may have enabled unauthorized access to certain customers' Salesforce data" through the connected app, and that it had revoked all active access and refresh tokens tied to Gainsight-published applications and temporarily removed them from AppExchange. Salesforce spokesperson Allen Tsai said there was "no indication that this issue resulted from any vulnerability in the Salesforce platform." Austin Larsen of Google Threat Intelligence Group said Google was "aware of more than 200 potentially affected Salesforce instances" and that the activity "is likely related to UNC6240 (aka ShinyHunters)". ShinyHunters told BleepingComputer it had reached another 285 Salesforce instances after breaching Gainsight using secrets stolen in the Salesloft Drift breach, and told The Register it had access for "nearly 3 months". Those are the attackers' claims. Zendesk and HubSpot cut their own connections to Gainsight as a precaution, and Palo Alto Networks disabled its Gainsight integration and later said it was not affected.

On 25 November Gainsight CEO Chuck Ganapathi wrote: "we presently know of only a handful of customers who had their data affected." Gainsight brought in Mandiant and later CrowdStrike. In a summary published on 2 January 2026, CTO Prem Parameswaran set out what they found. Mandiant received an email from the attacker on 20 November with a file of 285 Salesforce OAuth tokens for the integration. The attacker had tested about 250 tokens in bulk around 22 October 2025 and used the valid ones against customer orgs between 16 and 19 November, with no matching access to Gainsight's own systems. The newest token was created around August 2023 and the oldest in October 2017, and only about 23% still existed in Gainsight's systems. Investigators could not identify where the token set came from and found no evidence in the one-year log window that it came from Gainsight's systems.

That account differs from earlier reporting. BleepingComputer noted that Gainsight had previously confirmed it was breached through stolen OAuth tokens linked to Salesloft Drift, and ShinyHunters linked the two. Gainsight's investigation places the original exposure outside its forensic window. Its root-cause finding was blunt: "OAuth tokens were allowed to live too long."

Timeline

DateEvent
October 2017Oldest of the 285 stolen Gainsight OAuth tokens is created, according to Mandiant's findings as reported by Gainsight.
August 2023Newest of the stolen tokens is created.
22 October 2025The attacker tests about 250 tokens in bulk to see which still work.
16 November 2025The attacker starts calling Salesforce APIs against customer orgs with valid tokens, continuing to 19 November.
19 November 2025Salesforce contacts Gainsight, revokes all tokens for Gainsight-published apps, removes them from AppExchange and issues an advisory.
20 November 2025Google Threat Intelligence Group links the activity to ShinyHunters; Mandiant receives the attacker's file of 285 tokens.
21 November 2025ShinyHunters claims responsibility to The Register; Zendesk and HubSpot cut Gainsight connections.
25 November 2025Gainsight's CEO says only a handful of customers had data affected.
2 January 2026Gainsight publishes the Mandiant and CrowdStrike findings and its OAuth changes.

How it happened: the identity attack path

  1. Integration tokens issued and never expired. Each customer authorisation of the Gainsight connected app produced an OAuth refresh token that stayed valid until revoked, some for more than eight years.
  2. Tokens stolen from an unknown source. An attacker obtained a set of 285 of these tokens. Gainsight says investigators could not determine how; ShinyHunters claims it came through secrets from the Salesloft Drift breach.
  3. Bulk validation. Around 22 October 2025 the attacker tested about 250 tokens to find the ones that still worked.
  4. API access as the integration. From 16 to 19 November the attacker used valid tokens to call Salesforce APIs against customer orgs from infrastructure that was not Gainsight's.
  5. Detection by the platform. Salesforce spotted the unusual source of the requests, revoked every token for the Gainsight apps and notified affected customers.

Impact

  • Confirmed: unauthorised API access to some customers' Salesforce data using Gainsight's OAuth tokens, confirmed by Salesforce and Gainsight.
  • Scale, disputed: more than 200 potentially affected Salesforce instances according to Google Threat Intelligence Group; a handful of customers with data affected according to Gainsight; 285 instances claimed by ShinyHunters.
  • Service impact: a week after Salesforce's advisory, Gainsight's Salesforce integration was still disabled with no return date, and Zendesk and HubSpot had also cut their connections.
  • Potential: CRM records can hold contacts, support cases and, as the Salesloft Drift campaign showed, secrets that customers paste into cases, which an attacker can reuse elsewhere.

What this means for NHI governance

Gainsight is the same pattern as the Salesloft Drift breach and the earlier ShinyHunters Salesforce campaign: the attacker never needed a Salesforce password, only a token that a trusted integration already held. Every one of those tokens is a non-human identity with standing access to a customer's tenant. Few customers could have listed them, and nobody had rotated them.

The most useful part of this incident is Gainsight's own finding. Tokens created in 2017 still worked in 2025, and only 23% of them were still tracked in Gainsight's systems, so the vendor no longer knew it was responsible for most of them. The fixes it lists are standard OAuth hygiene: automatic rotation, single-use refresh tokens, trusted IP ranges and PKCE. Customers can apply the same ideas from their side by reviewing connected apps and restricting where they can be used. Our SaaS and OAuth App Governance Guide and OAuth 2.0 and OpenID Connect Guide go into detail.

Recommendations

  • Inventory connected apps and their tokens. List every connected app with access to your Salesforce and other SaaS tenants, who approved it and when its tokens were issued. See our SaaS and OAuth App Governance Guide.
  • Set refresh token expiry and rotation. Configure connected apps so refresh tokens expire or rotate, rather than living until revoked. See our Token and Session Security Guide.
  • Restrict integration traffic by IP. Limit each connected app to the vendor's published IP ranges, so stolen tokens fail from other infrastructure.
  • Monitor API use per integration. Alert on bulk queries, new source addresses and unusual objects accessed by integration users. See our ITDR Guide.
  • Revoke and rotate on vendor incidents. When a vendor reports suspicious activity, revoke its tokens, rotate any secrets stored in CRM records and review access logs. See our Leaked Credential Response Playbook.
  • Keep secrets out of CRM records. Support cases and notes are a common place for keys and passwords, and integration tokens can read them.

Frequently asked questions

What happened in the Gainsight Salesforce breach?

An attacker used OAuth tokens issued to Gainsight's Salesforce connected app to call Salesforce APIs against customer orgs between 16 and 19 November 2025. Salesforce detected the activity, revoked all tokens for Gainsight-published apps on 19 November and notified affected customers.

Who was behind the Gainsight breach?

Google Threat Intelligence Group said the activity was likely related to UNC6240, also known as ShinyHunters, and the group claimed responsibility to The Register. Gainsight's investigation could not determine how the attacker originally obtained the tokens.

Is the Gainsight breach linked to Salesloft Drift?

ShinyHunters claims it reached Gainsight using secrets stolen in the Salesloft Drift breach, and BleepingComputer reported that Gainsight had earlier confirmed a Drift-related compromise. Gainsight's later investigation found no evidence in its one-year log window that the token set came from its systems and says the original source is unknown.

Salesloft Drift breach 2025 · ShinyHunters Salesforce data theft 2025 · Commvault Metallic breach 2025 · SaaS and OAuth App Governance Guide · OAuth 2.0 and OpenID Connect Guide

How NHI Mgmt Group can help

OAuth tokens held by SaaS integrations are some of the least visible non-human identities in any organisation. We help teams discover them, set lifetimes and rotation, and build monitoring that spots a stolen token in use. See our NHI Foundation Level Training Course.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org