In late November 2025, Salesforce detected unauthorized access to customer data through misused OAuth tokens stemming from Gainsight integrations. Gainsight acknowledged the incident and engaged Mandiant for forensic analysis, confirming the issue was related to OAuth misuse rather than a Salesforce vulnerability. Salesforce subsequently revoked affected tokens and removed the relevant applications from its AppExchange.
The breach primarily involved CRM data, potentially impacting over 200 companies, with some estimates suggesting up to 1,000. The types of data accessed include account details, contact information, case details, opportunities, and user information. There has been no confirmation of whether SSN, medical, or financial data was exposed. The exact number of affected individuals remains unclear, as the impact is measured by companies compromised. While the full global scope is not yet specified, FINRA issued a cybersecurity alert in December 2025 to its member firms, indicating potential US impact.
More details may emerge as investigations continue, and affected parties may receive direct notifications.