HomeIntelligenceBrief
BREACH BRIEF🟠 High ThreatIntel

Data Theft Campaign Hijacks Salesforce and ServiceNow Accounts Across Multiple Sectors

The “City‑Forum” group has been stealing data from Salesforce and ServiceNow accounts since early 2025, targeting organizations in many industries. The campaign highlights gaps in credential hygiene and the need for SOC 2‑aligned access‑control evidence.

LiveThreat™ Intelligence · 📅 August 13, 2026· 📰 darkreading.com
🟠
Severity
High
TI
Type
ThreatIntel
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
darkreading.com

Data Theft Campaign Hijacks Salesforce and ServiceNow Accounts Across Multiple Sectors

What Happened — The “City‑Forum” threat group has been running a data‑theft operation since at least March 2025, using custom tooling to compromise user accounts on Salesforce and ServiceNow. The campaign spans a variety of industries, exfiltrating data from the targeted SaaS environments.

Why It Matters for Compliance & Audit Readiness

  • The attack exploits weak or reused credentials, a classic failure of SOC 2 logical‑access controls (CC6.1).
  • Continuous evidence of privileged‑account monitoring and MFA enforcement is essential to demonstrate due diligence during an audit.
  • Verisq’s SOC 2 Access Controls capability provides automated credential‑risk scoring and audit‑ready logs for SaaS platforms, turning the same data the attackers seek into compliance evidence.

Who Is Affected — Enterprises that rely on Salesforce (CRM) or ServiceNow (ITSM) across finance, healthcare, technology, and other sectors.

Recommended Actions

  • Conduct an immediate credential‑audit on all Salesforce and ServiceNow accounts; enforce MFA and least‑privilege assignments.
  • Enable continuous monitoring of privileged‑account activity and integrate logs into your SOC 2 evidence repository.
  • Update your SaaS vendor‑risk program to include periodic security‑posture reviews of third‑party applications. Source: Dark Reading

Technical Notes

  • Attack vector: stolen or weak credentials used to access SaaS APIs.
  • No specific CVE; the threat relies on credential reuse and insufficient MFA.
  • Data types exfiltrated include customer records, internal communications, and configuration metadata. Source: Dark Reading
📰 Original Source
https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your SOC 2 posture defensible.

See where you'd stand with Verisq AI Trust Operations →