Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
The Record from Recorded Future News

The Record from Recorded Future News Vendor Cyber Rating & Cyber Score

therecord.media

Recorded Future News is an independent team of global journalists reporting across all aspects of cybersecurity and intelligence. Launched in 2020, its news site The Record by Recorded Future News, and its flagship weekly podcast Click Here, give readers exclusive, behind-the-scenes access to the leaders, policymakers, researchers, and organizations shaping these fast-changing worlds. Read all of the latest headlines at therecord.media, tune into the Click Here podcast for new episodes each week, and follow us on Twitter at @TheRecord_Media and @ClickHereShow. Readers can also sign up to receive the latest news headlines directly via email by subscribing to the free CyberDaily newsletter.


RRFN A.I CyberSecurity Scoring

RRFN
Company Information
Website:https://therecord.media/
Employees number:14
Number of followers:14,360
NAICS:5191311
Industry Type:Internet News
Homepage:therecord.media
RRFN Risk Score (AI oriented)
Between 700 and 749
logo
RRFNInternet News
Updated:
28/03/2026
709/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
RRFN Global Score (TPRM)
xxxx
logo
RRFNInternet News
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

RRFN
RRFNModerate
Current Score
709Ba (MODERATE)
01000
3 incidents
-117.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
521Before Incident
JUNE 2026
517Before Incident
MAY 2026
710Before Incident
APRIL 2026
710Before Incident
MARCH 2026
708Before Incident
FEBRUARY 2026
708Before Incident
JANUARY 2026
707Before Incident
DECEMBER 2025
706Before Incident
NOVEMBER 2025
540Before Incident
Breach
24 Nov 2025RRFN
Salesforce

Salesforce Data Breach: ShinyHunters Hack via Gainsight Integration

482After Incident
CRITICAL-58
GAI1122911112425
The Salesforce data breach involved the ShinyHunters (UNC6240) hacking group, which exploited stolen OAuth tokens from Salesloft’s GitHub account to infiltrate Drift’s Salesforce integration and subsequently compromise Gainsight, a customer process management platform. The attackers gained unauthorized access to over 200 Salesforce instances, exfiltrating enterprise customer data through third-party service integrations (including HubSpot and Zendesk). While Salesforce revoked access keys and removed affected apps from the AppExchange, the breach exposed sensitive customer data, though the full scope of the leak remains undisclosed. The attack leveraged supply-chain vulnerabilities rather than a direct Salesforce platform flaw. ShinyHunters claimed delayed detection (1–2 weeks post-intrusion) and sought internal accomplices for further exploitation. Salesforce refused ransom demands, but the incident highlights risks in third-party integrations and credential-based attacks.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessSupply Chain Attack
MOTIVATION
Data TheftExtortionFinancial GainEspionage
IMPACT
Salesforce Instances (200+)GainsightSalesloftDriftHubSpotZendeskTemporary Disruption of Gainsight Apps on Salesforce AppExchangeLimited Functionality of HubSpot/Zendesk ConnectorsRevocation of Access KeysRemoval of Gainsight Apps from AppExchangeInternal Reviews by Affected CompaniesPotential Erosion of Trust in Salesforce EcosystemNegative Publicity for Gainsight, HubSpot, ZendeskHigh (Enterprise Customer Data Exposed)
DATA BREACH
Enterprise Customer DataCRM RecordsIntegration LogsSensitivity Of Data: High (Potential PII, Business-Critical CRM Data)Personally Identifiable Information: Likely (Enterprise Customer Data)
OCTOBER 2025
705Before Incident
SEPTEMBER 2025
704Before Incident
AUGUST 2025
702Before Incident
Breach
01 Aug 2025RRFN
Gainsight

Gainsight Unauthorized Salesforce Data Access via Stolen OAuth Tokens

525After Incident
CRITICAL-177
GAI0292402112125
The incident at Gainsight stemmed from a downstream effect of the August 2025 Salesloft breach, where the Scattered Lapsus$ Hunters group stole OAuth tokens tied to Salesloft’s Drift AI chat integration with Salesforce. These tokens granted unauthorized API access to 760 Salesforce instances, leading to the exfiltration of 1.5 billion records, including passwords, AWS keys, and Snowflake tokens.A subgroup, ShinyHunters, exploited the stolen credentials to breach Gainsight’s systems, extracting customer contact data (names, business emails, phone numbers, regional details), licensing information, and support case contents. Salesforce responded by revoking all active Gainsight-associated tokens and temporarily removing its apps from the AppExchange to mitigate further exposure. While Salesforce clarified that its platform itself was not vulnerable, the breach originated from Gainsight’s external app connections, compromising sensitive corporate and customer data across hundreds of organizations.
INCIDENT DETAILS -
TYPE
Data BreachUnauthorized AccessCredential Theft
MOTIVATION
Data TheftFinancial Gain (Potential Dark Web Sale)Reputation Damage
IMPACT
Salesforce Instances (760 in Salesloft breach)Gainsight-published ApplicationsToken RevocationAppExchange RemovalCustomer NotificationsLoss of TrustNegative PublicityBusiness Contact Details Exposed
DATA BREACH
Business Contact Details (Names, Emails, Phone Numbers)Licensing InformationSupport Case ContentsRegional/Location DetailsPasswords (Salesloft Breach)AWS Keys (Salesloft Breach)Snowflake Tokens (Salesloft Breach)1.5 Billion (Salesloft Breach)Undisclosed (Gainsight Breach)Moderate to High (Business PII, Credentials, API Keys)Business PII (Names, Emails, Phone Numbers)
DECEMBER 2024
751Before Incident
Breach
01 Dec 2024RRFN
Russian businesses using unlicensed software

RedLine Info-Stealing Campaign Targeting Russian Businesses

693After Incident
CRITICAL-58
THE000121024
An info-stealing campaign by RedLine targets Russian businesses that use pirated corporate software to automate business processes. Attackers distribute a malicious version of HPDxLIB activator on accounting forums, luring users to disable security measures and replace legitimate libraries with infected ones. The compromise leads to the theft of sensitive data, such as credentials and financial information, from businesses relying on these pirated solutions. This not only disrupts business operations but also poses a significant threat to the proprietors' privacy and the companies' financial integrity.
INCIDENT DETAILS -
TYPE
Info-Stealing
MOTIVATION
Data Theft
IMPACT
CredentialsFinancial InformationSystems Affected: Business Process Automation SoftwareOperational Impact: Disruption of Business OperationsIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
CredentialsFinancial InformationSensitivity Of Data: High

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for RRFN ?
?
What was RRFN's A.I Rankiteo Cyber Score in June 2026 ?
?
What was RRFN's A.I Rankiteo Cyber Score in May 2026 ?
?
What was RRFN's A.I Rankiteo Cyber Score in April 2026 ?
?
What was RRFN's A.I Rankiteo Cyber Score in March 2026 ?
?
What was RRFN's A.I Rankiteo Cyber Score in February 2026 ?
?
What was RRFN's A.I Rankiteo Cyber Score in January 2026 ?
?
What was RRFN's A.I Rankiteo Cyber Score in December 2025 ?
?
What was RRFN's A.I Rankiteo Cyber Score in November 2025 ?
?
What was RRFN's A.I Rankiteo Cyber Score in October 2025 ?
?
What was RRFN's A.I Rankiteo Cyber Score in September 2025 ?
?
What was RRFN's A.I Rankiteo Cyber Score in August 2025 ?
?
What is the average per-incident point impact on RRFN's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with RRFN ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view RRFN's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?