Unauthorized Data Extraction from Salesforce and ServiceNow Portals via Over-Privileged Guest Accounts
A single attacker has been scraping data from Salesforce and ServiceNow portals since 2025 using a server with a consistent fingerprint, exploiting over-privileged guest profiles to access sensitive information across multiple industries. The campaign highlights vulnerabilities in SaaS platforms' guest access configurations, requiring remediation through tighter access controls rather than endpoint changes.
A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco.
The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158.220.87.79, hosted on a
*** END OF TRANSMISSION ***