One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
Summary
A single attacker, operating under the moniker 'City Forum campaign,' has been scraping data from both Salesforce and ServiceNow customer portals across various industries for over a year. The campaign has been traced back to a single server hosted by a specific provider.
IFF Assessment
This campaign demonstrates a persistent threat actor successfully exfiltrating sensitive customer data from widely used SaaS platforms, posing a significant risk to organizations and their customers.
Defender Context
This incident highlights the ongoing risk of data scraping from cloud-based CRM and service management platforms. Defenders should ensure their configurations and access controls for Salesforce and ServiceNow are robust and regularly audited, and monitor for unusual data access patterns. This also emphasizes the need for comprehensive threat intelligence to identify and track persistent threat actors.