HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

Salesforce and ServiceNow Portals Exposed for 17 Months, Enabling Global Data Exfiltration

Researchers uncovered that a single server has been pulling data from publicly exposed Salesforce and ServiceNow portals for 17 months, compromising customer records. The incident highlights the need for continuous control mapping and audit‑ready evidence to satisfy SOC 2 requirements.

LiveThreat™ Intelligence · 📅 August 16, 2026· 📰 helpnetsecurity.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
helpnetsecurity.com

Salesforce and ServiceNow Portals Exposed for 17 Months, Enabling Global Data Exfiltration

What Happened — Researchers tracking the “City‑Forum” campaign discovered that a single rented server has been pulling records from publicly exposed Salesforce and ServiceNow portals worldwide for 17 months. The attackers accessed customer names, emails, and other business‑critical data without triggering any alerts.

Why It Matters for Compliance & Audit Readiness

  • This is a textbook example of a control gap that SOC 2 continuous‑compliance programs are built to detect and remediate through ongoing control mapping and evidence collection.
  • Demonstrating that access‑control policies, configuration reviews, and audit‑ready evidence are in place is essential to prove due diligence to auditors and regulators.
  • Leveraging Verisq’s Control Mapping capability provides immutable proof that portal configurations are regularly verified and that any deviation is captured as audit evidence.

Who Is Affected — SaaS providers (Salesforce, ServiceNow) and their enterprise customers across technology, finance, and professional services sectors.

Recommended Actions

  • Conduct an immediate inventory of all third‑party SaaS portals and verify that only authorized IP ranges and SSO integrations are allowed.
  • Map the portal‑access controls to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Access Management) and capture configuration snapshots as continuous evidence.
  • Implement automated alerts for any change in portal exposure status and integrate those alerts into your audit‑ready evidence repository.

Technical Notes – The attack leveraged publicly accessible endpoints (no authentication required) on Salesforce and ServiceNow instances, indicating a misconfiguration rather than credential theft. No specific CVE is cited; the exposure stemmed from improperly set “public link” settings. Source: Help Net Security

📰 Original Source
https://www.helpnetsecurity.com/2026/08/16/week-in-review-salesforce-and-servicenow-portals-exposed-for-17-months-exploited-metabase-0-day/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →