Salesforce and ServiceNow Portals Exposed for 17 Months, Enabling Global Data Exfiltration
What Happened — Researchers tracking the “City‑Forum” campaign discovered that a single rented server has been pulling records from publicly exposed Salesforce and ServiceNow portals worldwide for 17 months. The attackers accessed customer names, emails, and other business‑critical data without triggering any alerts.
Why It Matters for Compliance & Audit Readiness
- This is a textbook example of a control gap that SOC 2 continuous‑compliance programs are built to detect and remediate through ongoing control mapping and evidence collection.
- Demonstrating that access‑control policies, configuration reviews, and audit‑ready evidence are in place is essential to prove due diligence to auditors and regulators.
- Leveraging Verisq’s Control Mapping capability provides immutable proof that portal configurations are regularly verified and that any deviation is captured as audit evidence.
Who Is Affected — SaaS providers (Salesforce, ServiceNow) and their enterprise customers across technology, finance, and professional services sectors.
Recommended Actions
- Conduct an immediate inventory of all third‑party SaaS portals and verify that only authorized IP ranges and SSO integrations are allowed.
- Map the portal‑access controls to SOC 2 CC6.1 (Logical Access) and CC6.2 (User Access Management) and capture configuration snapshots as continuous evidence.
- Implement automated alerts for any change in portal exposure status and integrate those alerts into your audit‑ready evidence repository.
Technical Notes – The attack leveraged publicly accessible endpoints (no authentication required) on Salesforce and ServiceNow instances, indicating a misconfiguration rather than credential theft. No specific CVE is cited; the exposure stemmed from improperly set “public link” settings. Source: Help Net Security