gainsight-oauth-2025 · Disclosed 2025-11-20
Gainsight integration: old OAuth tokens reused against customer environments
Attackers tested old integration tokens and used still-valid credentials against Salesforce APIs. The original acquisition path is unidentified.
Outcome: Confirmed breach
Entry path and evidence
- Reported fact
Gainsight reports token validation on October 22 and customer Salesforce API calls on November 16–19, without corresponding recent access to Gainsight systems.
[s2]Analyzing the Token Usage - Reported fact
Even the newest token dated to August 2023. Investigators could not identify the leak source; Gainsight identifies long-lived validity as a systemic issue.
[s2]Analyzing the Token Origin / At the Root of the Issue
Timeline
Incident disclosed. [s1]
Reported response
- Reported fact
Gainsight reported credential rotation, stale-key removal, frequent token refresh, single-use refresh tokens, trusted IP restrictions, and PKCE.
[s2]Immediate Remediation / OAuth Token Lifecycle Management
Evidence relevant to prevention
Operational controls to inspect
Inspect OAuth lifetimes, refresh-token reuse controls, and legacy revocation evidence even when the leak source is unknown.
Editorial assessment; not a determination of liability. [s2]
Unknowns and AI involvement
The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.
The original source and leakage date are unknown; 2025 reuse does not establish a new breach of Gainsight itself.
Sources
[s1] Gainsight · Primary source
Salesforce–Gainsight Connected App Incident ↗Published 2025-11-20 · Reviewed 2026-10-02
[s2] Gainsight · Primary source
How We Accelerated a Year of Security Work in Weeks ↗Published 2026-01-02 · Reviewed 2026-10-02