One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
Overview
A single attacker has been extracting records from Salesforce and ServiceNow customer portals for over a year, according to research from Reco, a security platform. This activity, identified as the City Forum campaign, is traced back to a specific server with the IP address 158.220.87.79. The attack affects organizations across various industries that use these platforms, raising concerns about the security of sensitive customer data. The ongoing nature of this campaign suggests that organizations using Salesforce and ServiceNow must take immediate action to protect their data. This incident underscores the need for heightened vigilance and improved security measures in customer portal management.
Key Takeaways
- Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
- Affected Systems: Salesforce, ServiceNow
- Action Required: Organizations should review their portal security settings, implement stricter access controls, and monitor for unusual activities.
- Timeline: Ongoing since 2025
Original Article Summary
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158.220.87.79, hosted on a
Impact
Salesforce, ServiceNow
Exploitation Status
This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.
Timeline
Ongoing since 2025
Remediation
Organizations should review their portal security settings, implement stricter access controls, and monitor for unusual activities. Regular audits of user access and data handling processes are also recommended.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to Data Breach.