ShinyHunters vs Salesforce: A Dislike Revealed

by Anika Shah - Technology
0 comments

ShinyHunters Claims Obligation for Gainsight Breach,Links it to Salesloft/Drift Hack

ShinyHunters has claimed responsibility for the recent data breach at Gainsight,stating the incident allowed them to access data from hundreds of Salesforce customers.

In messages to The Register, a member of the extortion group saeid thay gained access to Gainsight nearly three months ago, during the earlier Salesloft Drift hack.

“The data from Salesloft Drift breached has enabled entry points into so many systems. Very lucrative systems,” the member, claiming to be “Shiny,” told The Register. “I do not like Salesforce at all, would be nice if they stopped acting all high and mighty and just pay to fix this mess.”

Gainsight has not yet responded to inquiries from The Register.

According to ShinyHunters, they also gained access to Gainsight during the Drift breaches.

Gainsight is a customer success platform that also integrates with salesforce and several other CRMs, including HubSpot, and also support tools like Zendesk.

In a Friday alertGainsight said it brought on Google’s Mandiant incident responders to assist with its ongoing investigation.

“We continue to work on the ongoing investigation into the connection issue affecting Gainsight-published applications on Salesforce,” the company said, noting that the “activity under investigation originated from the applications’ external connection – not from any issue or vulnerability within the Salesforce platform.”

Salesforce on Wednesday said it “revoked all active access and refresh tokens associated with Gainsight-published applications connected to Salesforce and temporarily removed those applications from the AppExchange while

Related Posts

Leave a Comment