The Containment Era is here. →Explore

Executive Summary

In November 2025, Gainsight disclosed an expansion of its impacted customer list following suspicious activity targeting its cloud applications within the Salesforce platform. Originally affecting three customers identified incidentally by Salesforce, the scope broadened as investigation revealed further unauthorized access to sensitive business data. The breach, detected through abnormal activity monitoring, prompted Gainsight to alert clients and coordinate remediation steps while collaborating with Salesforce to identify the root cause. The company has not shared the exact number of affected customers but confirmed exposure to confidential customer information, presenting new compliance and reputational challenges.

This incident reflects a continued surge in third-party and SaaS provider breaches, illustrating the interconnected risk facing organizations that rely on enterprise platforms. With attackers leveraging increasingly subtle lateral movement techniques and targeting east-west cloud traffic, robust zero trust controls and real-time anomaly detection are more critical than ever.

Why This Matters Now

The expanding scale of SaaS provider breaches elevates the urgency for organizations to implement strong east-west security, visibility, and policy controls across their cloud supply chain. As vendor incidents can quickly escalate, proactive segmentation and anomaly detection are essential to limit blast radius and sustain compliance.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The breach resulted from unauthorized access to Gainsight's Salesforce applications, likely exploiting gaps in east-west traffic security or insufficient privilege segmentation, leading to exposure of sensitive client data.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Applying CNSF Zero Trust controls—including segmentation, egress enforcement, encrypted traffic monitoring, and threat detection—would have limited movement, stopped mass exfiltration, and quickly identified unusual activities within cloud and SaaS ecosystems.

Initial Compromise

Control: Multicloud Visibility & Control

Mitigation: Early detection of unauthorized access and cloud application activity.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Minimized access scope to only what is necessary, reducing attacker's ability to escalate.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocked or flagged unauthorized workload/service-to-service access.

Command & Control

Control: Cloud Firewall (ACF)

Mitigation: Malicious C2 traffic is identified and contained.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Exfiltration attempts are blocked or logged for rapid response.

Impact (Mitigations)

Rapid detection and containment reduce blast radius and customer impact.

Impact at a Glance

Affected Business Functions

  • Customer Relationship Management
  • Sales Operations
  • Support Services
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Unauthorized access to customer contact details, emails, phone numbers, and support case contents.

Recommended Actions

  • Enforce zero trust segmentation and identity-based policies to minimize access after initial compromise.
  • Implement robust egress filtering to prevent unauthorized data exfiltration and block suspicious outbound connections.
  • Increase real-time visibility across multicloud and SaaS environments to detect abnormal access or privilege escalation.
  • Apply east-west traffic inspection and workload isolation to disrupt lateral movement within cloud fabrics.
  • Automate threat detection and response for early identification and rapid containment of suspicious activities.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image