Threat Intelligence

One Attacker's Server Has Been Quietly Scraping Salesforce and ServiceNow Data for Over a Year

The Hacker News · 18 Aug 2026
Key Takeaway If your business uses customer portals like Salesforce or ServiceNow, review access logs regularly and enable alerts for unusual or high-volume data requests.

Security researchers at Reco have uncovered a long-running campaign, dubbed 'City Forum', in which a single attacker-controlled server has been used to scrape data from customer portals built on both Salesforce and ServiceNow. The activity has reportedly been ongoing for more than a year and spans multiple industries, suggesting a broad and persistent targeting effort rather than an isolated incident.

The campaign traces back to one IP address, 158.220.87.79, which researchers linked to a domain that gave the campaign its name. The fact that a single piece of infrastructure has been used against two widely adopted enterprise platforms highlights how attackers are increasingly targeting customer-facing portals as a reliable source of business and customer data, rather than relying solely on traditional network intrusions.

For small and medium businesses that use Salesforce, ServiceNow, or similar customer portal platforms, this campaign is a reminder that these systems are attractive targets even when not directly breached through your own network. Portals often hold sensitive customer records, and scraping activity can go unnoticed for long periods if access logs and unusual traffic patterns aren't actively monitored.

Salesforce ServiceNow data scraping

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.