Data Theft Campaign Hijacks Salesforce and ServiceNow Accounts Across Multiple Sectors
What Happened — The “City‑Forum” threat group has been running a data‑theft operation since at least March 2025, using custom tooling to compromise user accounts on Salesforce and ServiceNow. The campaign spans a variety of industries, exfiltrating data from the targeted SaaS environments.
Why It Matters for Compliance & Audit Readiness
- The attack exploits weak or reused credentials, a classic failure of SOC 2 logical‑access controls (CC6.1).
- Continuous evidence of privileged‑account monitoring and MFA enforcement is essential to demonstrate due diligence during an audit.
- Verisq’s SOC 2 Access Controls capability provides automated credential‑risk scoring and audit‑ready logs for SaaS platforms, turning the same data the attackers seek into compliance evidence.
Who Is Affected — Enterprises that rely on Salesforce (CRM) or ServiceNow (ITSM) across finance, healthcare, technology, and other sectors.
Recommended Actions
- Conduct an immediate credential‑audit on all Salesforce and ServiceNow accounts; enforce MFA and least‑privilege assignments.
- Enable continuous monitoring of privileged‑account activity and integrate logs into your SOC 2 evidence repository.
- Update your SaaS vendor‑risk program to include periodic security‑posture reviews of third‑party applications. Source: Dark Reading
Technical Notes
- Attack vector: stolen or weak credentials used to access SaaS APIs.
- No specific CVE; the threat relies on credential reuse and insufficient MFA.
- Data types exfiltrated include customer records, internal communications, and configuration metadata. Source: Dark Reading