Close Menu
TechTost
  • AI
  • Apps
  • Crypto
  • Fintech
  • Hardware
  • Media & Entertainment
  • Security
  • Startups
  • Transportation
  • Venture
  • Recommended Essentials
What's Hot

India has changed its startup rules for deep tech

Backlash over OpenAI’s decision to withdraw GPT-4o shows how dangerous AI companions can be

Spotify upgrades its lyrics feature with offline access, more translations

Facebook X (Twitter) Instagram
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer
Facebook X (Twitter) Instagram
TechTost
Subscribe Now
  • AI

    Backlash over OpenAI’s decision to withdraw GPT-4o shows how dangerous AI companions can be

    8 February 2026

    New York lawmakers are proposing a three-year freeze on new data centers

    7 February 2026

    Benchmark raises $225 million in dedicated funds to double Cerebras

    7 February 2026

    How artificial intelligence is helping to solve the labor issue in treating rare diseases

    6 February 2026

    Amazon and Google are winning the AI ​​capital race — but what’s the prize?

    6 February 2026
  • Apps

    Spotify upgrades its lyrics feature with offline access, more translations

    8 February 2026

    After backlash, Adobe reverses shutdown of Adobe Animate and puts app in ‘maintenance mode’

    7 February 2026

    EU says TikTok must disable ‘addictive’ features like infinite scrolling, fix recommendation engine

    7 February 2026

    Here’s how Roblox’s age controls work

    6 February 2026

    Meta is testing a standalone app for its AI-generated ‘Vibes’ videos

    6 February 2026
  • Crypto

    Hackers stole over $2.7 billion in crypto in 2025, data shows

    23 December 2025

    New report examines how David Sachs may benefit from Trump administration role

    1 December 2025

    Why Benchmark Made a Rare Crypto Bet on Trading App Fomo, with $17M Series A

    6 November 2025

    Solana co-founder Anatoly Yakovenko is a big fan of agentic coding

    30 October 2025

    MoviePass opens Mogul fantasy league game to the public

    29 October 2025
  • Fintech

    Stripe Alumni Raise €30M Series A for Duna, Backed by Stripe and Adyen Executives

    5 February 2026

    Fintech CEO and Forbes 30 Under 30 alum indicted for alleged fraud

    3 February 2026

    How Sequoia-backed Ethos went public while rivals lagged behind

    30 January 2026

    5 days left for TechCrunch Disrupt 2026 +1 pass with 50%

    26 January 2026

    50% off +1 ends | TechCrunch

    23 January 2026
  • Hardware

    Kindle Scribe Colorsoft is an expensive but beautiful color e-ink tablet with AI features

    6 February 2026

    Ring brings “Search Party” feature for finding lost dogs to non-Ring camera owners

    2 February 2026

    India offers zero taxes till 2047 to attract global AI workloads

    1 February 2026

    Microsoft won’t stop buying AI chips from Nvidia, AMD even after its own is released, says Nadella

    30 January 2026

    The iPhone just had its best quarter ever

    30 January 2026
  • Media & Entertainment

    The “picked last in gym class” kids get ready for the Super Bowl

    8 February 2026

    From Svedka to Anthropic, Brands Are Making Bold Plays With AI in Super Bowl Ads

    7 February 2026

    “Industry” Season 4 captures tech fraud better than any show on TV right now

    7 February 2026

    Spotify’s new feature lets you explore the story behind the song you’re listening to

    6 February 2026

    The Washington Post retreats from Silicon Valley when it matters most

    6 February 2026
  • Security

    Senator, who has repeatedly warned of secret US government surveillance, raises new alarm over ‘CIA activities’

    7 February 2026

    Substack confirms that the data breach affects users’ email addresses and phone numbers

    6 February 2026

    One of Europe’s biggest universities was offline for days after the cyber attack

    6 February 2026

    Cyber ​​tech giant Conduent’s hot air balloon data breach affects millions more Americans

    5 February 2026

    Hackers Release Personal Information Stolen During Harvard, UPenn Data Breach

    5 February 2026
  • Startups

    Gradient’s heat pumps get new smarts to enable retrofitting of old buildings

    8 February 2026

    Accel doubles down on Fibr AI as agents turn static websites into one-to-one experiences

    7 February 2026

    ElevenLabs Raises $500M From Sequoia At $11B Valuation

    7 February 2026

    Fundamental raises $255 million in Series A with a new approach to big data analytics

    6 February 2026

    a16z VC wants founders to stop stressing about crazy ARR numbers

    6 February 2026
  • Transportation

    Prince Andrew’s adviser suggested Jeffrey Epstein invest in EV startups like Lucid Motors

    7 February 2026

    Apeiron Labs Takes $9.5M to Flood Oceans with Autonomous Underwater Robots

    5 February 2026

    Uber appoints new CFO as its AV plans accelerate

    5 February 2026

    Skyryse lands another $300 million to make flying, even helicopters, simple and safe

    4 February 2026

    China is leading the fight against hidden car door handles

    3 February 2026
  • Venture

    India has changed its startup rules for deep tech

    8 February 2026

    Peak XV Says Internal Disagreement Has Led to Partner Exits as AI Doubles

    8 February 2026

    SNAK Venture Partners raises $50 million in capital to support vertical acquisitions

    7 February 2026

    Reddit says it’s looking for more acquisitions in adtech and elsewhere

    7 February 2026

    Secondary sales are shifting from founders’ windfalls to employee retention tools

    6 February 2026
  • Recommended Essentials
TechTost
You are at:Home»Security»Google says hackers stole data from 200 companies after Gainsight breach
Security

Google says hackers stole data from 200 companies after Gainsight breach

techtost.comBy techtost.com22 November 202504 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Email
Google Says Hackers Stole Data From 200 Companies After Gainsight
Share
Facebook Twitter LinkedIn Pinterest Email

Google has confirmed that hackers have stolen the data of more than 200 companies stored in Salesforce in a large-scale supply chain hack.

On Thursday, Salesforce disclosed a breach of “certain customers’ Salesforce data” — without naming affected companies — that was stolen through apps published by Gainsight, which provides a customer support platform to other companies.

In a statement, Austin Larsen, principal threat analyst at Google’s Threat Intelligence Group, said the company is “aware of more than 200 potentially affected Salesforce instances.”

After Salesforce announced the breach, the infamous and somewhat nebulous hacking group known as Scattered Lapsus$ Hunters, which includes the ShinyHunters gang, claimed responsibility for the hacks in a Telegram channel seen by TechCrunch.

The hacking group claimed responsibility for the hacks affecting Atlassian, CrowdStrike, Docusign, F5, GitLab, Linkedin, Malwarebytes, SonicWall, Thomson Reuters and Verizon.

Contact us

Do you have more information about these Salesforce and Gainsight data breaches? Or other data breaches? From a non-working device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382 or via Telegram and Keybase @lorenzofb or via email.

Google will not comment on specific victims.

CrowdStrike spokesman Kevin Benacci told TechCrunch in a statement that the company “is not affected by the Gainsight issue and all customer data remains secure.” CrowdStrike confirmed to TechCrunch that it has ended a “suspicious tip” for allegedly passing information to hackers.

TechCrunch reached out to all the companies listed by Scattered Lapsus$ Hunters.

Verizon spokesman Kevin Israel said in a statement that “Verizon is aware of the unfounded claim by the threat actor,” without providing evidence for that claim.

Malwarebytes spokesperson Ashley Stewart told TechCrunch that the company’s security team is “aware” of the Gainsight and Salesforce issues and is “actively investigating the matter.”

A Thomson Reuters spokesman said the company was “actively investigating.”

Michael Adams, Docusign’s chief information security officer told TechCrunch in a statement that “after a comprehensive log analysis and internal investigation, we have no indication of a Docusign data breach at this time.” However, Adams said that, “out of an abundance of caution, we have taken certain steps, including terminating all Gainsight integrations and limiting related data flows.”

At the time of publication, none of the other companies responded to requests for comment.

Hackers from the group ShinyHunters told TechCrunch in an online chat that they gained access to Gainsight thanks to a previous hacking campaign targeting customers of Salesloft, which provides an AI and chatbot marketing platform called Drift. In that earlier case, hackers stole Drift authentication tokens from those customers, allowing hackers to break into connected Salesforce instances and download their content.

At the time, Gainsight confirmed were among the victims of this hacking campaign.

“Gainsight was a customer of Salesloft Drift, they were affected and therefore completely breached by us,” a representative of the ShinyHunters group told TechCrunch.

Salesforce spokeswoman Nicole Aranda told TechCrunch that “as a matter of policy, Salesforce does not comment on specific customer issues.”

Gainsight did not respond to TechCrunch’s requests for comment.

On Thursday, Salesforce he said There is “no indication that this issue arose from any vulnerability in the Salesforce platform,” effectively distancing itself from its customer data breaches.

Gainsight is posting updates about the incident on his incident page. On Friday, the company said it was now working with Google’s Mandiant incident response unit to help investigate the breach, that the incident “stemmed from external application connectivity — not an issue or vulnerability in the Salesforce platform” and that “a forensic analysis is ongoing as part of a comprehensive and independent investigation.”

“Salesforce has temporarily revoked active access tokens for applications connected to Gainsight as a precautionary measure while its investigation into unusual activity continues,” according to Gainsight’s incident page, which said Salesforce is notifying affected customers whose data has been stolen.

On its Telegram channel, Scattered Lapsus$ Hunters said it plans to open a dedicated website to blackmail victims of its latest campaign by next week. This is how the team works. In October, hackers also published a similar extortion site after victims’ Salesforce data was stolen in the Salesloft incident.

Scattered Lapsus$ Hunters is an English-speaking hacker group made up of various cybercriminal gangs, including ShinyHunters, Scattered Spider, and Lapsus$, whose members use social engineering tactics to trick company employees into giving hackers access to their systems or databases. In recent years, these groups have claimed several high-profile victims, including MGM Resorts, Coinbase, DoorDash and others.

This story has been updated to include comments from Docusign, Thomson Reuters and Verizon.

breach Companies cyber attack cyber security data data breach Gainsight Google hacker hackers Hacking profit Salesforce Scattered Lapsus$ Hunters Scattered Spider shine hunters stole
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleBret Taylor’s Sierra hits $100M ARR in less than two years
Next Article Pew’s latest social media report shows X staying in the US, despite the competition
bhanuprakash.cg
techtost.com
  • Website

Related Posts

New York lawmakers are proposing a three-year freeze on new data centers

7 February 2026

Senator, who has repeatedly warned of secret US government surveillance, raises new alarm over ‘CIA activities’

7 February 2026

Substack confirms that the data breach affects users’ email addresses and phone numbers

6 February 2026
Add A Comment

Leave A Reply Cancel Reply

Don't Miss

India has changed its startup rules for deep tech

8 February 2026

Backlash over OpenAI’s decision to withdraw GPT-4o shows how dangerous AI companions can be

8 February 2026

Spotify upgrades its lyrics feature with offline access, more translations

8 February 2026
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Fintech

Stripe Alumni Raise €30M Series A for Duna, Backed by Stripe and Adyen Executives

5 February 2026

Fintech CEO and Forbes 30 Under 30 alum indicted for alleged fraud

3 February 2026

How Sequoia-backed Ethos went public while rivals lagged behind

30 January 2026
Startups

Gradient’s heat pumps get new smarts to enable retrofitting of old buildings

Accel doubles down on Fibr AI as agents turn static websites into one-to-one experiences

ElevenLabs Raises $500M From Sequoia At $11B Valuation

© 2026 TechTost. All Rights Reserved
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms and Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.