One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
What Happened — A single IP address (158.220.87.79) was observed pulling records from Salesforce and ServiceNow customer portals for more than a year. The activity, dubbed the City Forum campaign by Reco, spanned multiple industries and involved automated scraping of data exposed through the SaaS portals.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a failure of SOC 2 Access Control criteria: inadequate credential hygiene, insufficient MFA enforcement, and lack of continuous monitoring of privileged API access.
- Continuous‑compliance programs must capture immutable logs of SaaS access, prove least‑privilege provisioning, and provide audit‑ready evidence that anomalous data‑exfiltration attempts are detected and blocked.
Who Is Affected — Organizations that rely on Salesforce (CRM) or ServiceNow (ITSM) for customer or internal data, across finance, healthcare, manufacturing, and other sectors.
Recommended Actions
- Review and tighten SaaS access policies: enforce MFA, rotate API keys, and apply least‑privilege principles.
- Enable and centralize audit logging for all SaaS integrations; set up alerts for bulk‑download patterns.
- Conduct a SOC 2 Access Controls gap analysis and map remediation steps to the Trust Services Criteria.
Source: The Hacker News
Technical Notes — The attacker leveraged a compromised set of credentials (likely API tokens) to automate data scraping via the standard web portals. No specific CVE is cited; the vector is credential compromise and insufficient monitoring of privileged SaaS access.