Close Menu
Xarkas BlogXarkas Blog
    What's Hot

    Trump administration might not fight state AI regulations after all

    November 23, 2025

    Lava Agni 4 India Launch at 12 noon Today: How to Watch the Livestream? Check Expected Price & Specifications

    November 23, 2025

    Fallout 4 Just Hit Its Lowest Rating and It’s Really No Surprise

    November 23, 2025
    Facebook X (Twitter) Instagram
    Xarkas BlogXarkas Blog
    • Tech News

      Trump administration might not fight state AI regulations after all

      November 23, 2025

      Byju’s founder to appeal U.S. court order to pay over $1B in bankruptcy case

      November 23, 2025

      Meta wants to get into the electricity trading business

      November 22, 2025

      Phictly’s new app brings people together over their favorite books and TV shows

      November 22, 2025

      X begins rolling out the ‘About this account’ feature to users’ profiles

      November 22, 2025
    • Mobiles

      Lava Agni 4 India Launch at 12 noon Today: How to Watch the Livestream? Check Expected Price & Specifications

      November 23, 2025

      Lava Agni 4 Launched in India: Check Price, Specs, Features

      November 22, 2025

      iQOO 15 Price in India Revealed Through Amazon Listing Ahead of Launch on November 26

      November 22, 2025

      OnePlus 15R Price in India Tipped Ahead of Launch in India: Check Full Specifications Here

      November 22, 2025

      iQOO 15 Pre-Booking Starts Today: How to Reserve Your Priority Pass

      November 22, 2025
    • Gaming

      Fallout 4 Just Hit Its Lowest Rating and It’s Really No Surprise

      November 23, 2025

      It Will Be Easier to Win in Fortnite This Weekend

      November 23, 2025

      How to Fight Solus Heart in Risk of Rain 2 Alloyed Collective

      November 22, 2025

      The Game Awards 2025 Continues Xbox’s Unfortunate GOTY Streak

      November 22, 2025

      Black Flag’s Remake May Be Bringing Back Cut Content, But There’s One Storyline That Deserves It the Most

      November 22, 2025
    • SEO Tips
    • PC/ Laptops

      ASUS Unveils ProArt P16 Laptop For Creators In India

      November 18, 2025

      Apple Reportedly Reserving OLED Displays for M6 Pro and M6 Max MacBook Pro Models

      November 10, 2025

      Apple Reportedly Working on a Budget MacBook Featuring iPhone Chip: Expected Launch and Price

      November 5, 2025

      Acer Predator Helios Neo 16 AI and 16S AI Gaming Laptops Launched in India: Check Pricing and Specifications

      November 4, 2025

      COLORFUL Launches Rimbook L1: Affordable Laptop For Everyday Use

      November 4, 2025
    • EV

      Here’s How Much It Costs

      November 15, 2025

      Sodium-Ion Batteries Have Landed In America. The Hard Part Starts Now

      November 15, 2025

      Mazda Begins Testing Its Long-Overdue U.S. EV

      November 14, 2025

      Volkswagen Adds Smartwatch Support For U.S. Vehicles

      November 14, 2025

      TATA.ev expands charging footprint with 14 new manned MegaChargers across AP, Telangana

      November 14, 2025
    • Gadget
    • AI
    Facebook
    Xarkas BlogXarkas Blog
    Home - Featured - Google says hackers stole data from 200 companies following Gainsight breach
    Featured

    Google says hackers stole data from 200 companies following Gainsight breach

    KavishBy KavishNovember 22, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Google says hackers stole data from 200 companies following Gainsight breach
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Google has confirmed that hackers have stolen the Salesforce-stored data of more than 200 companies in a large-scale supply chain hack.

    On Thursday, Salesforce disclosed a breach of “certain customers’ Salesforce data” — without naming affected companies — that was stolen via apps published by Gainsight, which provides a customer support platform to other companies.  

    In a statement, Austin Larsen, the principal threat analyst of Google Threat Intelligence Group, said that the company “is aware of more than 200 potentially affected Salesforce instances.”

    After Salesforce announced the breach, the notorious and somewhat-nebulous hacking group known as Scattered Lapsus$ Hunters, which includes the ShinyHunters gang, claimed responsibility for the hacks in a Telegram channel, which TechCrunch has seen. 

    The hacking group claimed responsibility for hacks affecting Atlassian, CrowdStrike, Docusign, F5, GitLab, Linkedin, Malwarebytes, SonicWall, Thomson Reuters, and Verizon.

    Contact Us

    Do you have more information about these Salesforce and Gainsight data breaches? Or other data breaches? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.

    Google would not comment on specific victims.

    CrowdStrike’s spokesperson Kevin Benacci told TechCrunch in a statement that the company is “not affected by the Gainsight issue and all customer data remains secure.” CrowdStrike confirmed to TechCrunch that it terminated a “suspicious insider” for allegedly passing information to hackers.

    TechCrunch reached out to all the companies mentioned by Scattered Lapsus$ Hunters.

    Verizon spokesperson Kevin Israel said in a statement that “Verizon is aware of the unsubstantiated claim by the threat actor,” without providing evidence for this claim.

    Malwarebytes spokesperson Ashley Stewart told TechCrunch that the company’s security team is “aware” of the Gainsight and Salesforce issues and “actively investigating the matter.”

    A spokesperson for Thomson Reuters said the company is “actively investigating.”

    Michael Adams, the chief information security officer at Docusign told TechCrunch in a statement that “following a comprehensive log analysis and internal investigation, we have no indication of Docusign data compromise at this time.” However, Adams said that, “out of an abundance of caution, we have taken a number of measures including terminating all Gainsight integrations and containing related data flows.”

    At the time of publishing, none of the other companies responded to requests for comment.

    Hackers with the ShinyHunters group told TechCrunch in an online chat that they gained access to Gainsight thanks to their previous hacking campaign that targeted customers of Salesloft, which provides an AI and chatbot-powered marketing platform called Drift. In that earlier case, the hackers stole Drift authentication tokens from those customers, allowing the hackers to break into their linked Salesforce instances and download their contents.

    At the time, Gainsight confirmed it was among the victims of that hacking campaign. 

    “Gainsight was a customer of Salesloft Drift, they were affected and therefore compromised entirely by us,” a spokesperson for the ShinyHunters group told TechCrunch.

    Salesforce spokesperson Nicole Aranda told TechCrunch that “as a matter of policy, Salesforce does not comment on specific customer issues.”

    Gainsight did not respond to TechCrunch’s requests for comment.

    On Thursday, Salesforce said there is “no indication that this issue resulted from any vulnerability in the Salesforce platform,” effectively distancing itself from its customers’ data breaches.

    Gainsight has been publishing updates about the incident on its incident page. On Friday, the company said that it is now working with Google’s incident response unit Mandiant to help investigate the breach, that the incident in question “originated from the applications’ external connection — not from any issue or vulnerability within the Salesforce platform,” and that “a forensic analysis is continuing as part of a comprehensive and independent review.”

    “Salesforce has temporarily revoked active access tokens for Gainsight-connected apps as a precautionary measure while their investigation into unusual activity continues,” according to Gainsight’s incident page, which said Salesforce is notifying affected customers whose data was stolen. 

    In its Telegram channel, Scattered Lapsus$ Hunters said it plans to launch a dedicated website to extort the victims of its latest campaign by next week. This is the group’s modus operandi; in October, the hackers also published a similar extortion website after stealing victims’ Salesforce data in the Salesloft incident. 

    The Scattered Lapsus$ Hunters is a collective of English-speaking hackers made up of several cybercriminal gangs, including ShinyHunters, Scattered Spider, and Lapsus$, whose members use social engineering tactics to trick company employees into granting the hackers access to their systems or databases. In the last few years, these groups have claimed several high-profile victims, such as MGM Resorts, Coinbase, DoorDash, and more.

    This story was updated to include comments from Docusign, Thomson Reuters, and Verizon.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Kavish
    • Website

    Related Posts

    Trump administration might not fight state AI regulations after all

    November 23, 2025

    Lava Agni 4 India Launch at 12 noon Today: How to Watch the Livestream? Check Expected Price & Specifications

    November 23, 2025

    Fallout 4 Just Hit Its Lowest Rating and It’s Really No Surprise

    November 23, 2025

    Byju’s founder to appeal U.S. court order to pay over $1B in bankruptcy case

    November 23, 2025

    It Will Be Easier to Win in Fortnite This Weekend

    November 23, 2025

    Meta wants to get into the electricity trading business

    November 22, 2025

    Comments are closed.

    Top Reviews
    Editors Picks

    Trump administration might not fight state AI regulations after all

    November 23, 2025

    Lava Agni 4 India Launch at 12 noon Today: How to Watch the Livestream? Check Expected Price & Specifications

    November 23, 2025

    Fallout 4 Just Hit Its Lowest Rating and It’s Really No Surprise

    November 23, 2025

    Byju’s founder to appeal U.S. court order to pay over $1B in bankruptcy case

    November 23, 2025
    About Us
    About Us

    Email Us: info@xarkas.com

    Facebook Pinterest
    © 2025 . Designed by Xarkas Technologies.
    • Home
    • Mobiles
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.