Executive Summary
In June 2024, Salesforce launched an investigation after a supply chain breach at Gainsight, a software vendor, resulted in the theft of certain Salesforce customer data. Attackers exploited compromised Gainsight credentials to gain unauthorized access to customer information via third-party OAuth apps. Salesforce responded quickly by revoking refresh tokens linked to impacted Gainsight-published integrations and advised customers to take precautionary steps, including reviewing and rotating their credentials. While the breach did not affect Salesforce’s internal systems, it highlighted the significant risk posed by interconnected software supply chains and third-party integrations.
This incident underscores the increasing sophistication of supply chain attacks targeting cloud platforms and SaaS providers. As businesses rely more heavily on integrated services and external vendors, attackers are exploiting trust relationships to bypass traditional security controls, emphasizing the urgent need for robust third-party risk management and continuous monitoring.
Why This Matters Now
The Salesforce-Gainsight breach illustrates how attackers increasingly target trusted software suppliers to access sensitive customer data, making supply chain security an urgent priority. Organizations must assess third-party connections and enforce strong access controls to prevent similar incidents as dependency on external vendors continues to grow.
Attack Path Analysis
Attackers initially compromised Gainsight, a Salesforce supply chain partner, leveraging its application integration to gain access to customer data. They likely escalated privileges within Gainsight or Salesforce’s cloud environment, obtaining additional access or token capabilities. This enabled lateral movement through connected cloud resources or SaaS integrations. Attackers established a persistent command and control channel using legitimate refresh tokens or cloud-native APIs. Data was then exfiltrated from Salesforce environments or via manipulated Gainsight applications to external locations. The impact resulted in unauthorized theft of sensitive customer data and forced token revocation to mitigate ongoing risk.
Kill Chain Progression
Initial Compromise
Description
Compromise of the Gainsight SaaS provider, leveraging its integration with Salesforce to gain initial foothold in customer environments via trusted application ties.
MITRE ATT&CK® Techniques
Supply Chain Compromise
Valid Accounts
Account Manipulation
Unsecured Credentials
Data from Cloud Storage Object
Exfiltration Over Web Service
Application Layer Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Service Provider Risk Management
Control ID: 12.8.4
NYDFS 23 NYCRR 500 – Third Party Service Provider Security Policy
Control ID: 500.11
DORA – ICT Third-Party Risk Management
Control ID: Article 28
NIS2 Directive – Supply Chain Security
Control ID: Article 21(2)d
CISA ZTMM 2.0 – Continuous Authentication
Control ID: Identity Pillar - 3.2
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Supply chain compromise through Salesforce-Gainsight integration exposes customer data, requiring enhanced zero trust segmentation and egress security controls.
Financial Services
Third-party SaaS breaches threaten sensitive financial data, demanding stricter multicloud visibility controls and encrypted traffic protection for compliance.
Health Care / Life Sciences
Patient data exposure via compromised refresh tokens violates HIPAA requirements, necessitating threat detection and anomaly response capabilities.
Information Technology/IT
IT service providers face cascading supply chain risks from SaaS integrations, requiring cloud native security fabric and kubernetes protection.
Sources
- Salesforce investigates customer data theft via Gainsight breachhttps://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/Verified
- Salesforce says some of its customers’ data was accessed after Gainsight breachhttps://techcrunch.com/2025/11/20/salesforce-says-some-of-its-customers-data-was-accessed-after-gainsight-breach/Verified
- Google says hackers stole data from 200 companies following Gainsight breachhttps://techcrunch.com/2025/11/21/google-says-hackers-stole-data-from-200-companies-following-gainsight-breach/Verified
- Salesforce flags another third-party security incidenthttps://www.theregister.com/2025/11/20/salesforce_gainsight_breach/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Enforcing zero trust segmentation, centralized policy enforcement, and egress controls in both cloud and SaaS environments would have drastically limited the attackers’ movement post-compromise and detected anomalous data access or exfiltration. CNSF-aligned controls like least-privilege segmentation, egress policy enforcement, and continuous monitoring provide layered defense, minimizing lateral movement and data leakage via integrated third parties.
Control: Zero Trust Segmentation
Mitigation: Limited application-to-application access stops broad exploitation of SaaS integrations.
Control: Multicloud Visibility & Control
Mitigation: Early detection and alerting on anomalous privilege increases.
Control: East-West Traffic Security
Mitigation: Prevents unauthorized internal movement between workloads and services.
Control: Threat Detection & Anomaly Response
Mitigation: Rapid detection and alerting on covert command and anomalous SaaS activity.
Control: Egress Security & Policy Enforcement
Mitigation: Blocks unauthorized outbound data flows and SaaS-to-external transfers.
Limits blast radius and enables fast, automated remediation.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management
- Sales Operations
- Marketing Campaigns
Estimated downtime: 7 days
Estimated loss: $5,000,000
Unauthorized access to Salesforce data through compromised Gainsight applications potentially exposed sensitive customer information, including contact details, sales records, and marketing data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement zero trust segmentation between SaaS integrations and sensitive cloud workloads to prevent unauthorized access paths.
- • Enforce centralized egress policies to monitor and control all outbound data flows, especially from third-party SaaS connectors.
- • Deploy continuous threat detection and anomaly response across cloud and SaaS environments to rapidly identify credential abuse and privilege escalation.
- • Increase multicloud and SaaS visibility to detect abnormal identities, token usage, and cross-environment pivots.
- • Regularly audit and harden permissions for all integrated SaaS applications, revoking excessive access and enforcing least privilege.



