One Attacker's Server Has Been Quietly Scraping Salesforce and ServiceNow Data for Over a Year
Security researchers at Reco have uncovered a long-running campaign, dubbed 'City Forum', in which a single attacker-controlled server has been used to scrape data from customer portals built on both Salesforce and ServiceNow. The activity has reportedly been ongoing for more than a year and spans multiple industries, suggesting a broad and persistent targeting effort rather than an isolated incident.
The campaign traces back to one IP address, 158.220.87.79, which researchers linked to a domain that gave the campaign its name. The fact that a single piece of infrastructure has been used against two widely adopted enterprise platforms highlights how attackers are increasingly targeting customer-facing portals as a reliable source of business and customer data, rather than relying solely on traditional network intrusions.
For small and medium businesses that use Salesforce, ServiceNow, or similar customer portal platforms, this campaign is a reminder that these systems are attractive targets even when not directly breached through your own network. Portals often hold sensitive customer records, and scraping activity can go unnoticed for long periods if access logs and unusual traffic patterns aren't actively monitored.