Guest User Misconfiguration Enables 17‑Month Data Harvest from Salesforce and ServiceNow Portals
What Happened — Researchers tracking the “City‑Forum” campaign observed an unauthenticated actor repeatedly querying public Salesforce Experience Cloud and ServiceNow portals via their built‑in guest‑user accounts. Over 17 months the actor harvested records from dozens of organizations—including telecoms, banks, and public‑sector agencies—without exploiting a software flaw or stealing credentials.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of an over‑permissive guest‑user configuration that bypasses the “need‑to‑know” principle, a control explicitly required by SOC 2 CC6.1 (Logical Access).
- Continuous evidence of proper guest‑user permission reviews and automated control mapping can demonstrate due diligence to auditors and reduce the risk of undisclosed data exposure.
- Verisq’s Control Mapping capability provides a real‑time view of guest‑user permissions against SOC 2 requirements and captures immutable audit evidence for the Trust Center.
Who Is Affected — Telecom operators, banks & financial‑services firms, enterprise‑software vendors, security‑and‑privacy solution providers, and public‑sector agencies that expose Salesforce Experience Cloud or ServiceNow knowledge‑base portals.
Recommended Actions
- Conduct an immediate inventory of all guest‑user accounts in Salesforce and ServiceNow; verify that their permission sets align with the principle of least privilege.
- Implement a continuous monitoring rule that flags any guest‑user permission changes and logs access attempts for audit review.
- Map the guest‑user access control to SOC 2 CC6.1 and capture the evidence in a centralized Trust Center for future audits.
Technical Notes – The attacker leveraged no vulnerability; the vector was a misconfiguration of the default guest‑user profile, allowing enumeration of Aura framework objects in Salesforce and unrestricted reads in ServiceNow. No CVE is associated. Source: Help Net Security