HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Attacker Scraped Salesforce and ServiceNow Portals for Over a Year, Exposing Customer Records

A single server has been pulling data from Salesforce and ServiceNow portals across multiple industries since 2025. The breach highlights gaps in SaaS credential management and continuous monitoring—key SOC 2 access‑control requirements.

LiveThreat™ Intelligence · 📅 August 18, 2026· 📰 thehackernews.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
4 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

What Happened — A single IP address (158.220.87.79) was observed pulling records from Salesforce and ServiceNow customer portals for more than a year. The activity, dubbed the City Forum campaign by Reco, spanned multiple industries and involved automated scraping of data exposed through the SaaS portals.

Why It Matters for Compliance & Audit Readiness

  • The incident exemplifies a failure of SOC 2 Access Control criteria: inadequate credential hygiene, insufficient MFA enforcement, and lack of continuous monitoring of privileged API access.
  • Continuous‑compliance programs must capture immutable logs of SaaS access, prove least‑privilege provisioning, and provide audit‑ready evidence that anomalous data‑exfiltration attempts are detected and blocked.

Who Is Affected — Organizations that rely on Salesforce (CRM) or ServiceNow (ITSM) for customer or internal data, across finance, healthcare, manufacturing, and other sectors.

Recommended Actions

  • Review and tighten SaaS access policies: enforce MFA, rotate API keys, and apply least‑privilege principles.
  • Enable and centralize audit logging for all SaaS integrations; set up alerts for bulk‑download patterns.
  • Conduct a SOC 2 Access Controls gap analysis and map remediation steps to the Trust Services Criteria.

Source: The Hacker News

Technical Notes — The attacker leveraged a compromised set of credentials (likely API tokens) to automate data scraping via the standard web portals. No specific CVE is cited; the vector is credential compromise and insufficient monitoring of privileged SaaS access.

📰 Original Source
https://thehackernews.com/2026/08/one-attacker-has-scraped-both.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · SOC 2 Readiness

Could you prove your access controls held up here?

Credential and access failures map directly to SOC 2 access-control criteria. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →