/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google confirms hackers stole Salesforce-stored data from 200+ companies via a supply chain hack involving Gainsight, which provides a customer support platform

Google has confirmed that hackers have stolen the Salesforce-stored data of more than 200 companies in a large-scale supply chain hack.

TechCrunch Lorenzo Franceschi-Bicchierai

Context & Ripple Effects

This adds a new supplier pathway to an existing Salesforce data-theft arc. Earlier coverage tied a campaign to compromised OAuth tokens in Salesloft's Drift integration, while a later claim described records from hundreds of Salesforce-using companies being taken through that route at far larger alleged scale.

The Gainsight incident matters because it puts another customer-facing SaaS provider in the chain between enterprises and data held in Salesforce, widening the practical scope of third-party access reviews.

First-order effects

  • The more than 200 affected companies must assess what Salesforce-held data was taken and manage customer, employee, and partner exposure from the theft.
  • Gainsight and Salesforce face immediate scrutiny over the access paths and integrations that connected Gainsight's service to customers' Salesforce data.

Second-order effects

  • Enterprise buyers will re-evaluate permissions, token scope, and monitoring for customer-support and other connected SaaS tools, rather than treating the core CRM platform as the sole security boundary.
  • Competing support-platform and integration vendors will be pressed to demonstrate stronger controls around customer data access, especially where a single service connects to many tenants.

Third-order effects

  • If incidents continue to span multiple SaaS integrations, third-party identity and authorization controls—not only application vulnerabilities—will become the central unit of enterprise data-risk management.
  • The pattern could push vendors and customers toward more segmented, revocable access architectures, though the corpus does not establish which technical or contractual model will prevail.

The trend: Enterprise breaches are increasingly concentrating in the permissions and integrations that connect cloud software vendors to shared stores of customer data.

Discussion

  • @lorenzofb Lorenzo Franceschi-Bicchierai on bluesky
    NEW: Google says the new wave of supply chain attacks by Scattered Lapsus$ Hunters impacted more than 200 companies' Salesforce-stored data.  —  Hackers said they breached CrowdStrike, Linkedin, Malwarebytes, Verizon etc.  —  Malwarebytes said is investigating.  CrowdStrike said …