Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Gainsight

Gainsight Vendor Cyber Rating & Cyber Score

gainsight.com

At Gainsight, our mission is to be living proof you can win in business while being human first. Gainsight, the world’s leading Customer Success platform, helps businesses drive efficient growth by unifying the post-sales customer journey. Our innovative suite of solutions—including customer success, customer education, product experience, community management, and conversational AI insights—are trusted by companies of all sizes and industries, including nearly 200 publicly traded organizations. With Gainsight, businesses can leverage AI-driven insights from real-time customer interactions to enhance engagement, improve retention, and drive expansion. Our platform makes it easier for customer success, product, and community teams to


Gainsight A.I CyberSecurity Scoring

Gainsight
Company Information
Website:https://www.gainsight.com
Employees number:1,099
Number of followers:158,852
NAICS:5112
Industry Type:Software Development
Homepage:gainsight.com
Gainsight Risk Score (AI oriented)
Between 0 and 549
logo
GainsightSoftware Development
Updated:
31/03/2026
313/1000
Critical
C
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Gainsight Global Score (TPRM)
xxxx
logo
GainsightSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Gainsight
GainsightCritical
Current Score
313C (CRITICAL)
01000
6 incidents
-94 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
334Before Incident
MAY 2026
322Before Incident
APRIL 2026
321Before Incident
MARCH 2026
369Before Incident
Breach
10 Mar 2026Gainsight
Salesforce: Threat actors use custom AuraInspector to harvest data from Salesforce systems

Threat Actors Exploit Modified AuraInspector Tool to Harvest Data from Misconfigured Salesforce Sites

307After Incident
CRITICAL-62
SAL1773146972
Threat Actors Exploit Modified AuraInspector Tool to Harvest Data from Misconfigured Salesforce Sites On March 10, 2026, Salesforce’s Cybersecurity Operations Center (CSOC) warned of a campaign in which threat actors are mass-scanning publicly accessible Salesforce Experience Cloud sites using a modified version of the AuraInspector tool. Originally developed by Google/Mandiant, AuraInspector is an open-source command-line utility designed to audit Salesforce Aura and Experience Cloud applications for data exposure risks by simulating unauthenticated or guest user access. Attackers have adapted the tool to exploit overly permissive guest user settings, enabling them to extract sensitive CRM data including Accounts, Contacts, and Leads via exposed Aura endpoints, record lists, or GraphQL controllers. While the original AuraInspector only identifies vulnerabilities, the modified version actively harvests data from misconfigured environments. Salesforce confirmed that the activity does not stem from a platform vulnerability but rather from customer misconfigurations, particularly in Experience Cloud guest user permissions. Exposed data could be leveraged for targeted social engineering or vishing attacks. The company attributes the campaign to a known threat actor group, potentially ShinyHunters, which has previously targeted Salesforce environments through third-party applications. Salesforce advises organizations to review and secure guest user settings, restrict public access, disable unnecessary APIs, and monitor logs to mitigate risks.
INCIDENT DETAILS -
TYPE
Data Harvesting
MOTIVATION
Data exfiltration for targeted social engineering or vishing attacks
IMPACT
Data Compromised: Accounts, Contacts, Leads (CRM data)Systems Affected: Salesforce Experience Cloud sitesIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: CRM data (Accounts, Contacts, Leads)Sensitivity Of Data: High (personally identifiable information)Data Exfiltration: YesPersonally Identifiable Information: Yes
FEBRUARY 2026
366Before Incident
JANUARY 2026
456Before Incident
DECEMBER 2025
447Before Incident
NOVEMBER 2025
506Before Incident
Breach
24 Nov 2025Gainsight
Salesforce

Salesforce Data Breach: ShinyHunters Hack via Gainsight Integration

444After Incident
CRITICAL-62
GAI1122911112425
The Salesforce data breach involved the ShinyHunters (UNC6240) hacking group, which exploited stolen OAuth tokens from Salesloft’s GitHub account to infiltrate Drift’s Salesforce integration and subsequently compromise Gainsight, a customer process management platform. The attackers gained unauthorized access to over 200 Salesforce instances, exfiltrating enterprise customer data through third-party service integrations (including HubSpot and Zendesk). While Salesforce revoked access keys and removed affected apps from the AppExchange, the breach exposed sensitive customer data, though the full scope of the leak remains undisclosed. The attack leveraged supply-chain vulnerabilities rather than a direct Salesforce platform flaw. ShinyHunters claimed delayed detection (1–2 weeks post-intrusion) and sought internal accomplices for further exploitation. Salesforce refused ransom demands, but the incident highlights risks in third-party integrations and credential-based attacks.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessSupply Chain Attack
MOTIVATION
Data TheftExtortionFinancial GainEspionage
IMPACT
Salesforce Instances (200+)GainsightSalesloftDriftHubSpotZendeskTemporary Disruption of Gainsight Apps on Salesforce AppExchangeLimited Functionality of HubSpot/Zendesk ConnectorsRevocation of Access KeysRemoval of Gainsight Apps from AppExchangeInternal Reviews by Affected CompaniesPotential Erosion of Trust in Salesforce EcosystemNegative Publicity for Gainsight, HubSpot, ZendeskHigh (Enterprise Customer Data Exposed)
DATA BREACH
Enterprise Customer DataCRM RecordsIntegration LogsSensitivity Of Data: High (Potential PII, Business-Critical CRM Data)Personally Identifiable Information: Likely (Enterprise Customer Data)
OCTOBER 2025
502Before Incident
SEPTEMBER 2025
497Before Incident
AUGUST 2025
645Before Incident
Breach
01 Aug 2025Gainsight
Gainsight

Gainsight Unauthorized Salesforce Data Access via Stolen OAuth Tokens

487After Incident
CRITICAL-158
GAI0292402112125
The incident at Gainsight stemmed from a downstream effect of the August 2025 Salesloft breach, where the Scattered Lapsus$ Hunters group stole OAuth tokens tied to Salesloft’s Drift AI chat integration with Salesforce. These tokens granted unauthorized API access to 760 Salesforce instances, leading to the exfiltration of 1.5 billion records, including passwords, AWS keys, and Snowflake tokens.A subgroup, ShinyHunters, exploited the stolen credentials to breach Gainsight’s systems, extracting customer contact data (names, business emails, phone numbers, regional details), licensing information, and support case contents. Salesforce responded by revoking all active Gainsight-associated tokens and temporarily removing its apps from the AppExchange to mitigate further exposure. While Salesforce clarified that its platform itself was not vulnerable, the breach originated from Gainsight’s external app connections, compromising sensitive corporate and customer data across hundreds of organizations.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessCredential Theft
MOTIVATION
Data TheftFinancial Gain (Potential Dark Web Sale)Reputation Damage
IMPACT
Salesforce Instances (760 in Salesloft breach)Gainsight-published ApplicationsToken RevocationAppExchange RemovalCustomer NotificationsLoss of TrustNegative PublicityBusiness Contact Details Exposed
DATA BREACH
Business Contact Details (Names, Emails, Phone Numbers)Licensing InformationSupport Case ContentsRegional/Location DetailsPasswords (Salesloft Breach)AWS Keys (Salesloft Breach)Snowflake Tokens (Salesloft Breach)1.5 Billion (Salesloft Breach)Undisclosed (Gainsight Breach)Moderate to High (Business PII, Credentials, API Keys)Business PII (Names, Emails, Phone Numbers)
Ransomware
01 Aug 2025Gainsight
Oracle

Clop Ransomware Exploits Oracle E-Business Suite Zero-Day (CVE-2025-61882) in Data Theft Attacks

487After Incident
CRITICAL-158
ORA1692116100725
The Clop ransomware gang exploited a critical zero-day vulnerability (CVE-2025-61882) in Oracle E-Business Suite (EBS), specifically within the BI Publisher Integration component, to conduct data theft attacks since at least August 2025. The flaw allowed unauthenticated remote code execution (RCE) via a single HTTP request, enabling attackers to steal sensitive corporate documents from unpatched systems. Oracle patched the vulnerability in early October 2025, but not before Clop launched an extortion campaign, emailing executives at multiple victim organizations to demand ransoms in exchange for not leaking the stolen data.The attack leveraged a vulnerability chain exposed by leaked proof-of-concept (PoC) exploits from the Scattered Lapsus$ Hunters group, increasing the risk of further exploitation by other threat actors. Clop’s campaign mirrors past high-profile breaches, including MOVEit Transfer (2,770+ organizations affected), Accellion FTA, and GoAnywhere MFT, reinforcing its reputation for large-scale data theft via zero-days. Oracle urged immediate patching, warning that internet-exposed EBS applications remain prime targets. The U.S. State Department has even offered a $10 million reward for intelligence linking Clop to foreign state sponsorship, underscoring the attack’s severity.
INCIDENT DETAILS -
TYPE
Data TheftRansomware ExtortionZero-Day Exploitation
MOTIVATION
Financial Gain (Extortion)Data Theft for Leverage
IMPACT
Sensitive DocumentsPotentially PII or Corporate DataOracle E-Business Suite (EBS) with unpatched BI Publisher IntegrationHigh (due to extortion and potential data leaks)Potential (if PII was stolen)
DATA BREACH
Sensitive Corporate DocumentsPotentially PIIHigh (confidential business documents)Confirmed (by Clop for extortion)Possible (not explicitly confirmed)
JULY 2025
645Before Incident
JUNE 2025
703Before Incident
Breach
05 Jun 2025Gainsight
Gainsight

Gainsight Data Breach Impacting Salesforce Customer Tokens

641After Incident
CRITICAL-62
GAI3653836120125
Gainsight, a customer management software firm, experienced a security breach that compromised a limited number of its clients' data. The incident was confirmed by CEO Chuck Ganapathi and involved the exposure of Salesforce customer tokens, which are critical for authentication and access control within Salesforce ecosystems. While the breach did not result in a large-scale data leak, the compromise of these tokens poses risks such as unauthorized access to customer accounts, potential phishing attacks, or further exploitation of linked systems. The breach highlights vulnerabilities in third-party integrations, particularly those tied to major platforms like Salesforce. Although the impact was contained to a subset of clients, the exposure of authentication tokens could lead to reputational damage for Gainsight, erosion of customer trust, and potential financial repercussions if affected clients face downstream security incidents. The company has not disclosed whether the breach was due to a targeted cyber attack, a vulnerability exploitation, or an internal misconfiguration, but the involvement of Salesforce tokens suggests a sophisticated intrusion method.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Salesforce customer tokens
DATA BREACH
Salesforce customer tokensSensitivity Of Data: High (authentication tokens)
MAY 2025
762Before Incident
Breach
15 May 2025Gainsight
Gainsight

Gainsight Data Breach Impacting Salesforce Customer Tokens

702After Incident
CRITICAL-60
GAI55104855112725
Gainsight, a customer success management software firm, experienced a security breach that compromised a limited number of its clients' data. The incident was linked to the exposure of Salesforce customer tokens, which are critical for authentication and access within the Salesforce ecosystem. CEO Chuck Ganapathi confirmed that while the breach impacted Gainsight’s systems, only a subset of clients had their data compromised. The nature of the breach suggests unauthorized access to sensitive customer-related credentials, potentially enabling further exploitation if misused. Although the exact scope of the stolen data remains undisclosed, the involvement of Salesforce tokens indicates a risk of downstream attacks, such as unauthorized access to client accounts or systems integrated with Gainsight. The breach underscores vulnerabilities in third-party SaaS platforms and the cascading risks posed by credential-based attacks in enterprise software supply chains.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Salesforce customer tokens
DATA BREACH
Salesforce customer tokensSensitivity Of Data: High (authentication tokens)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Gainsight ?
?
What was Gainsight's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Gainsight's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Gainsight's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Gainsight's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Gainsight's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Gainsight's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Gainsight's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Gainsight's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Gainsight's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Gainsight's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Gainsight's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Gainsight's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Gainsight ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Gainsight's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?