← Incident database

gainsight-oauth-2025 · Disclosed 2025-11-20

Gainsight integration: old OAuth tokens reused against customer environments

Attackers tested old integration tokens and used still-valid credentials against Salesforce APIs. The original acquisition path is unidentified.

CredentialsCause unresolved / undisclosed

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Gainsight reports token validation on October 22 and customer Salesforce API calls on November 16–19, without corresponding recent access to Gainsight systems.

    [s2]Analyzing the Token Usage
  • Reported fact

    Even the newest token dated to August 2023. Investigators could not identify the leak source; Gainsight identifies long-lived validity as a systemic issue.

    [s2]Analyzing the Token Origin / At the Root of the Issue

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Gainsight reported credential rotation, stale-key removal, frequent token refresh, single-use refresh tokens, trusted IP restrictions, and PKCE.

    [s2]Immediate Remediation / OAuth Token Lifecycle Management

Evidence relevant to prevention

Operational controls to inspect

Inspect OAuth lifetimes, refresh-token reuse controls, and legacy revocation evidence even when the leak source is unknown.

Editorial assessment; not a determination of liability. [s2]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

The original source and leakage date are unknown; 2025 reuse does not establish a new breach of Gainsight itself.

Sources

  1. [s1] Gainsight · Primary source

    Salesforce–Gainsight Connected App Incident ↗

    Published 2025-11-20 · Reviewed 2026-10-02

  2. [s2] Gainsight · Primary source

    How We Accelerated a Year of Security Work in Weeks ↗

    Published 2026-01-02 · Reviewed 2026-10-02