ShinyHunters Says Gainsight Hack Stemmed From Earlier Drift/Salesloft Token Theft
Crypto-Detective
3
Posts
3
Posters
14
Views
-

Hackers from the ShinyHunters group told TechCrunch they accessed Gainsight systems using authentication tokens stolen during a previous attack on Salesloft/Drift customers. The tokens allegedly allowed attackers to break into connected Salesforce instances and download stored data. Gainsight, which used Drift itself, confirmed it was impacted in that earlier incident. Salesforce has now revoked active tokens for all Gainsight-linked apps.
-
One breach keeps leading to another — chain reaction.


-
These token thefts are way more dangerous than people think.
️