William Cochran · November 12, 2025
Supply Chain Attacks: When Your Vendor’s Vendor Gets Breached
Salesforce Gainsight supply chain breach affected 200+ companies. Learn how supply chain attacks work and how to protect your business from vendor compromises.
Salesforce disclosed this month that hackers linked to the ShinyHunters group exploited Gainsight OAuth integrations to access data from over 200 companies. The attackers did not breach Salesforce directly — they compromised a third-party integration that many Salesforce customers had connected to their environments.
This is a supply chain attack, and it is one of the most dangerous trends in cybersecurity.
How Supply Chain Attacks Work
Instead of attacking your business directly — which might have strong defenses — attackers go after a vendor, plugin, or integration that has access to your systems. When they compromise that third party, they get access to every organization that third party is connected to.
It is like a thief who does not break into your house but instead steals the key from your cleaning service. One compromise, hundreds of victims.
Why This Is Getting Worse
Modern businesses use dozens of interconnected cloud services. Each integration — every OAuth connection, every API key, every single sign-on link — is a potential entry point. Most businesses do not have a complete inventory of these connections, let alone a risk assessment for each one.
What You Can Do
Inventory your integrations. What third-party applications have access to your critical systems? What permissions do they have? Many businesses are surprised to find integrations they forgot about or that former employees set up.
Apply least privilege. Every integration should have only the minimum permissions it needs to function. If a tool only needs to read data, it should not have write access.
Review vendor security. When evaluating vendors, ask about their security practices. Do they have SOC 2 certification? How do they handle vulnerabilities? What is their incident response plan?
Monitor for unusual activity. Even with good prevention, detection matters. Monitor your systems for unusual access patterns, especially from third-party integrations.
Concerned about your vendor exposure? Our compliance service includes a review of third-party risk.
Supply chain attacks exploit the trust between businesses and their vendors. That trust is necessary — you cannot run a modern business in isolation. But trust needs to be verified, documented, and monitored. That is part of what we do at Black Lab Solutions.