Salesforce and ServiceNow Portals Under Attack: The Data-Theft Campaign You Missed

·
Listen to this article~5 min

A data theft campaign is exploiting Salesforce Experience Cloud and ServiceNow portals, using custom tools to steal data exposed to anonymous users. Learn how to protect your organization.

An ongoing data theft campaign is quietly targeting some of the biggest names in enterprise software. If your company uses Salesforce Experience Cloud or ServiceNow customer portals, this is something you need to understand right now. The attackers aren't breaking in through elaborate hacks or zero-day exploits. Instead, they're using custom-built tools to siphon data that's already exposed to anonymous users. It's a reminder that sometimes the biggest risks aren't the locked doors—it's the ones we leave open. ### What's Happening in This Campaign This isn't your typical phishing scheme or ransomware attempt. The campaign relies on a simple but devastating premise: many organizations configure their customer portals to share information with unauthenticated visitors. That's by design—it's how customers check order statuses, submit tickets, or access knowledge bases. But the attackers have figured out how to abuse that openness. They've developed custom scripts that systematically crawl through these portals, pulling out any data that's accessible without a login. Think about what that could mean: - Customer names and contact details - Order histories and transaction records - Internal notes or support ticket content - Any file attachments that were mistakenly left public The scary part? This isn't a one-off exploit. The researchers tracking this say it's an ongoing operation, with new tools being refined and deployed continuously. ### Why Salesforce and ServiceNow Are Prime Targets Both platforms are massive. Salesforce Experience Cloud powers everything from partner communities to customer support hubs. ServiceNow handles IT service management, HR workflows, and customer service portals for thousands of enterprises. That scale makes them attractive. A single misconfigured portal could expose data for millions of end users. And because these platforms are so customizable, it's easy for an organization to accidentally leave a field or file open that shouldn't be. It's like leaving your garage door open in a busy neighborhood. Most people won't walk in, but someone with a specific interest in your stuff might take a peek. Now imagine that garage is full of customer records. ### How the Attackers Operate The campaign uses what researchers describe as "custom tools." These aren't off-the-shelf hacking utilities. They're purpose-built to interact with the specific APIs and structures of these platforms. The attackers appear to have deep knowledge of how Salesforce and ServiceNow handle public-facing content. They know where the gaps tend to be, and they've automated the process of finding and extracting that data. What's particularly concerning is the stealth factor. Since the data is technically public, the traffic doesn't look malicious at first glance. It just looks like a user browsing the portal. That makes detection harder for security teams. ### What You Can Do Right Now If you're running either of these platforms, don't panic—but do take action. Here are a few practical steps: - **Audit your public-facing pages.** Log out of your portal and browse it like a stranger would. See what's actually visible. - **Review API permissions.** Make sure anonymous access is only enabled for the specific endpoints that need it. - **Check your logs for unusual crawling patterns.** High volumes of requests from a single IP or user agent could be a red flag. - **Work with your security team** to run a data exposure assessment focused on unauthenticated access. It's also worth reaching out to your Salesforce or ServiceNow account team. They can help you review your configuration and lock down anything that shouldn't be public. > "The most dangerous vulnerabilities aren't always the ones in the code. Sometimes they're in the configuration." — A security researcher's reminder ### The Bigger Picture This campaign is a wake-up call. The cloud platforms we rely on are powerful, but they're only as secure as we configure them. Data theft doesn't always involve sophisticated malware. Sometimes it's just about finding the open door. Take a few minutes today to check what your portals are exposing. It might save you from a very uncomfortable conversation with your customers later. Stay safe out there, and remember: the best security is the kind that never gets tested.