Same Threat Actor Has Been Harvesting Data from Salesforce and ServiceNow Since 2025

Same Threat Actor Has Been Harvesting Data from Salesforce and ServiceNow Since 2025

A single attacker has been quietly collecting information from public or poorly secured Salesforce and ServiceNow portals for over a year, security researchers say. The activity highlights the risk of misconfigured cloud…

Security researchers have identified a single threat actor who has been scraping data from both Salesforce and ServiceNow portals since 2025. Scraping means using automated software to copy information that is visible on a website or online service. In this case, the attacker appears to have been collecting data from these two widely used business platforms over an extended period. Salesforce is a customer relationship management (CRM) system, which companies use to store details about their customers, sales leads, and support cases. ServiceNow is a service management platform that many organizations use to handle IT requests, human resources tasks, and internal workflows. Both systems often contain sensitive business information, and when their portals are left open or poorly protected, that data can be copied by outsiders.

Why would one attacker target both Salesforce and ServiceNow? These platforms are extremely common in large and medium sized companies. Many organizations customize them with public facing portals for customers, partners, or employees. A portal is simply a web page that gives users access to certain data or tools. If the permissions on a portal are too broad, or if guest access is enabled without proper restrictions, an attacker can automate the process of pulling out records. The fact that a single attacker has been active since 2025 suggests that they are methodically looking for exposed data across multiple services. Security researchers often track such activity by observing the same patterns, internet addresses, or tool signatures. For website owners and IT teams, this is a reminder that cloud platforms are not secure by default and that settings need regular review.

The impact of this kind of scraping can be serious even if the attacker does not directly break into a database. Scraped data may include customer names, email addresses, phone numbers, support ticket details, and sometimes more sensitive records. Once that information is copied, it can be used for phishing attacks, identity theft, spam, or sold on underground markets. For a business, a scraping incident can damage customer trust and may violate data protection laws such as the General Data Protection Regulation (GDPR) in Europe. Many companies do not immediately notice that their portal is being scraped because the activity looks like normal web traffic. However, continuous automated requests from the same source can be a red flag. If an attacker has been doing this since 2025, it means that many organizations may have been affected without knowing it. The longer the exposure continues, the larger the amount of data that can be collected.

There are several steps that organisations and everyday internet users can take to reduce the risk from portal scraping. First, if you administer a Salesforce or ServiceNow instance, check the sharing settings for all public pages and guest user profiles. Make sure that only the minimum necessary data is accessible without a login. Second, enable multi factor authentication (MFA) for all administrative accounts, because a scraper might later use collected information to try to break into accounts. Third, monitor access logs for unusual patterns, such as a high volume of requests from a single internet address or requests for many records in a short time. Fourth, review the permissions of any connected applications or integrations, because these can sometimes expose data unintentionally. For ordinary users who do not manage a platform but who may have an account on sites built with Salesforce or ServiceNow, the main advice is to be cautious about what personal information you enter into web forms and to use unique passwords.

For businesses that are not sure whether their cloud portals are properly locked down, working with a security focused IT provider can help. AEU-I offers security first IT, infrastructure and consulting services that include reviewing cloud configurations and permissions. An assessment of this kind can identify which settings leave data visible to scrapers and help teams close those gaps before an attacker takes advantage. Even if your organisation does not use Salesforce or ServiceNow, the same principles apply to any web based system that holds customer or employee data. Regularly auditing access controls is one of the most effective ways to prevent automated data collection.

How to Protect Yourself

  1. If you manage a Salesforce or ServiceNow account, log in and check the sharing settings for any pages that are visible without a password; turn off public access unless you really need it.
  2. Turn on multi factor authentication (MFA), which asks for a second step like a code from your phone, for all accounts that can change settings or see customer data.
  3. Review who can view records in your portal and set permissions so that only the minimum necessary information is available to outside visitors.
  4. Use unique, strong passwords for any account connected to these platforms so that if scraped data includes a login name, attackers cannot reuse your password elsewhere.
  5. If you are not sure how to check these settings, ask a security professional or your IT provider to run a configuration review for cloud portal exposure.

Related AEU services

  • AEU Data Cloud and data infrastructure