CYBERSECURITYTRACKER
TRACKING
Permanent story citation

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4586

As cited

Copy frozen at (site build).

breaches incidents

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A single server has been scraping customer data from Salesforce and ServiceNow portals across multiple industries since early 2025, according to research by security platform Reco. The campaign, tracked as City Forum, uses infrastructure tied to one IP address for what appears to be coordinated data extraction.

Why it matters: Organizations using Salesforce and ServiceNow should investigate whether their customer portals have been accessed by the IP 158.220.87.79 and audit for unauthorized data exfiltration from their instances.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

A single server has been scraping customer data from Salesforce and ServiceNow portals across multiple industries since early 2025, according to research by security platform Reco. The campaign, tracked as City Forum, uses infrastructure tied to one IP address for what appears to be coordinated data extraction.

Why it matters: Organizations using Salesforce and ServiceNow should investigate whether their customer portals have been accessed by the IP 158.220.87.79 and audit for unauthorized data exfiltration from their instances.

VendorsSalesforceServiceNow
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary