← All briefs
high November 23, 2025

Salesforce Deployment Compromise via Gainsight Application

Source report →

Salesforce reported detecting unusual activity involving the AppExchange Gainsight application, which is installed and managed by Salesforce customers. According to Salesforce, the observed behavior may have allowed unauthorized access to customer data via the app’s connection. No vulnerabilities were reported within Salesforce’s platform itself. Salesforce disabled the OAuth connection for all Gainsight-published applications on November 20, 2025, suspending their ability to interact with Salesforce environments until further notice.

Salesforce emphasized that the revokation of OAuth tokens does not affect historical logs or audit data. Customers retain access to Setup Audit Trails, Event Monitoring logs, and API records to support their investigations. While Salesforce suggests reviewing these logs for potential compromise, it remains unconfirmed whether the root cause lies solely with the Gainsight application or its integration configuration.

IP ADDRESS 16
104.3.11.1
198.54.135.148
198.54.135.197
198.54.135.205
146.70.171.216
169.150.203.245
172.113.237.48
45.149.173.227
135.134.96.76
65.195.111.21
65.195.105.81
65.195.105.153
45.66.35.35
146.70.174.69
82.163.174.83
3.239.45.43

Detections

Additional detection ideas (1)
  • Monitor third-party vendor access for unusual activity patterns or access outside normal business hours