Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Proposed Data Centers Could Use More Electricity Than All Alabama Homes Combined, Analysis Shows. Who Will Pay?

    August 19, 2026

    After 25 years, I’m breaking up with The Sims. Here’s why you should, too | Jordan Erica Webber

    August 19, 2026

    China: Alleged sexual assault by local official and businessman in Hangzhou sparks outrage

    August 19, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Proposed Data Centers Could Use More Electricity Than All Alabama Homes Combined, Analysis Shows. Who Will Pay?
    • After 25 years, I’m breaking up with The Sims. Here’s why you should, too | Jordan Erica Webber
    • China: Alleged sexual assault by local official and businessman in Hangzhou sparks outrage
    • Trump hits pause on new Canada tariffs
    • How one man gets new laws passed – again and again
    • The Left Notches Another Win With This Secret Weapon: Old-Fashioned Organizing
    • Flock Has a Powerful New AI Tool for Police. We Got Its Code
    • 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Wednesday, August 19
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 19, 2026 Cybersecurity No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The Hacker NewsAug 18, 2026SaaS Security / Cloud Security

    A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco.

    The activity, which Reco has named the City Forum campaign after a domain tied to the attacker’s IP address, traces back to one server: 158.220.87.79, hosted on a commodity VPS through the German provider Contabo. Every request from that server carries the same fingerprint, the default user agent of Go’s net/http library, which tells researchers the tool behind it is a compiled, purpose built program rather than anything run from a browser. Passive DNS shows the same domain pointed at that IP as far back as March 2025, and the server has not moved since. Targets identified so far span telecoms, banks and other financial services firms, enterprise software vendors including security and data privacy companies, and public sector portals, though Reco has not named individual organizations.

    What sets this campaign apart from prior Salesforce guest access abuse, including the widely reported activity attributed to ShinyHunters, is the range of surfaces it touches. Most known attackers in this space lean on Salesforce’s older Aura framework, sending high volumes of guest requests to enumerate objects and page through records. This actor does that too, and Aura still accounts for the bulk of the traffic Reco observed, with one target logging over 560,000 events from the same IP. But the tool also reaches Salesforce’s newer Lightning Web Runtime sites through the UI-API, a data layer that has no public write ups or known scanning tools associated with it, walking through API versions v56.0 through v66.0 in sequence. On top of that, the same server hammers a native ServiceNow Service Portal search endpoint, POST /api/now/sp/search, that carries almost no public documentation of its own.

    According to Reco’s writeup, the common thread across every technique is the same underlying issue: a guest identity that was granted more access than the site actually needed to serve the public. Salesforce Experience Cloud sites and ServiceNow portals both maintain a persistent guest user that unauthenticated visitors execute as, and that user cannot be deleted, only restricted. If the guest profile can read a record, the record is effectively public, whether or not the site requires login to view it in a browser.

    The research lays out concrete detection steps for security and IT teams on both platforms. On Salesforce, defenders with Event Monitoring or Shield can pull AuraRequest and Sites log events and look for the Go-http-client user agent, the specific IP, and request paths containing /webruntime/api/services/data, alongside spikes in self registration attempts at /SiteRegister and /CommunitiesSelfReg. On ServiceNow, the transaction log table syslog_transaction can be filtered by source IP and by URLs starting with /api/now/sp/search, with guest created rows and unusual output length flagged as the clearest signal of a live sweep.

    Remediation, per the research, centers on tightening the guest profile rather than the endpoints themselves, since both the UI-API and the ServiceNow search endpoint are working as designed. On Salesforce, that means reviewing guest sharing rules, stripping unnecessary object and field level access from the guest profile, disabling self registration where it is not required, and turning off the Experience Builder setting that allows guest users to reach public APIs. On ServiceNow, the fix is mapping which search sources are exposed to public facing portals and auditing the Knowledge Base read criteria that decide what an anonymous search actually returns.

    Reco says the infrastructure behind the campaign is still active and the volume is climbing, and the firm has not attributed the activity to a specific named group.

    The full technical breakdown, including request signatures, sample queries, and a closer look at how the Service Portal search endpoint decides what to hand back to an anonymous caller, is available in Reco’s writeup of the City Forum campaign.

    Security leaders weighing how much of their budget to put toward this kind of app exposure, versus other priorities competing for the same dollars, can find a planning framework in Reco’s guide to AI security investment, which covers how to size budget, evaluate vendors, and build a business case for the board.

    Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

    attacker portals Salesforce Scraped ServiceNow
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets

    Microsoft working on Defender patch for ShieldBreak zero-day

    Heights Finance Data Breach Impacts at Least 1.2 Million Individuals

    Philips and GE investigating Clop ransomware data theft claims

    Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000

    Critical GitLab Zero-Click Flaw Poses Mitigation Challenges

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Proposed Data Centers Could Use More Electricity Than All Alabama Homes Combined, Analysis Shows. Who Will Pay?

    August 19, 2026

    After 25 years, I’m breaking up with The Sims. Here’s why you should, too | Jordan Erica Webber

    August 19, 2026

    China: Alleged sexual assault by local official and businessman in Hangzhou sparks outrage

    August 19, 2026

    Trump hits pause on new Canada tariffs

    August 19, 2026
    Latest Posts

    Tether’s XAUT Gains Shariah Certification for Islamic Finance

    July 27, 2026

    Nvidia and Tech Giants Launch AI Security Alliance

    July 27, 2026

    Perplexity Releases pplx, a Single-Binary CLI That Puts Its Search API in the Terminal for Coding Agents

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Proposed Data Centers Could Use More Electricity Than All Alabama Homes Combined, Analysis Shows. Who Will Pay?

    August 19, 2026

    After 25 years, I’m breaking up with The Sims. Here’s why you should, too | Jordan Erica Webber

    August 19, 2026

    China: Alleged sexual assault by local official and businessman in Hangzhou sparks outrage

    August 19, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.