Mystery attacker spent a year raiding Salesforce and ServiceNow portals
A mystery attacker used custom tools to exploit over-permissioned guest accounts on Salesforce and ServiceNow portals, conducting a year-long raid to harvest data.
A mystery attacker spent a year raiding Salesforce and ServiceNow portals, using custom tools to harvest data from over-permissioned guest accounts. The campaign exploited misconfigurations that granted excessive access to guest users, enabling prolonged data theft without detection. The attacker specifically targeted guest accounts—often used for external collaboration—that were left with unnecessary permissions. The breach underscores the risk of lax access controls in cloud-based customer relationship and service management platforms. The attacker’s identity remains unknown, and the full scope of stolen data is unclear.