Google Says Hackers Stole Data From Over 200 Companies Following Gainsight Breach (techcrunch.com)
(Friday November 21, 2025 @05:40PM (msmash)
from the worrisome-development dept.)
- Reference: 0180170307
- News link: https://tech.slashdot.org/story/25/11/21/1858250/google-says-hackers-stole-data-from-over-200-companies-following-gainsight-breach
- Source link: https://techcrunch.com/2025/11/21/google-says-hackers-stole-data-from-200-companies-following-gainsight-breach/
Google confirmed in a statement Friday that hackers have [1]stolen the Salesforce-stored data of more than 200 companies in a large-scale supply chain hack. TechCrunch reports:
> On Thursday, Salesforce disclosed a breach of "certain customers' Salesforce data" -- without naming affected companies -- that was stolen via apps published by Gainsight, which provides a customer support platform to other companies.
>
> In a statement, Austin Larsen, the principal threat analyst of Google Threat Intelligence Group, said that the company "is aware of more than 200 potentially affected Salesforce instances." After Salesforce announced the breach, the notorious and somewhat-nebulous hacking group known as Scattered Lapsus$ Hunters, which includes the ShinyHunters gang, claimed responsibility for the hacks in a Telegram channel, which TechCrunch has seen.
[1] https://techcrunch.com/2025/11/21/google-says-hackers-stole-data-from-200-companies-following-gainsight-breach/
> On Thursday, Salesforce disclosed a breach of "certain customers' Salesforce data" -- without naming affected companies -- that was stolen via apps published by Gainsight, which provides a customer support platform to other companies.
>
> In a statement, Austin Larsen, the principal threat analyst of Google Threat Intelligence Group, said that the company "is aware of more than 200 potentially affected Salesforce instances." After Salesforce announced the breach, the notorious and somewhat-nebulous hacking group known as Scattered Lapsus$ Hunters, which includes the ShinyHunters gang, claimed responsibility for the hacks in a Telegram channel, which TechCrunch has seen.
[1] https://techcrunch.com/2025/11/21/google-says-hackers-stole-data-from-200-companies-following-gainsight-breach/
Why is Google telling us about this? (Score:2)
Why isn't Salesforce telling us about this, and not Google? I'd say that's a massive red flag for anyone using Salesforce if they're hiding this sort of information.