Back to News
Cybersecurity

Long-Term Data Scraping Campaign Targets Salesforce and ServiceNow Portals

A single attacker has been continuously scraping data from Salesforce and ServiceNow portals since 2025, raising concerns for businesses across sectors.

Recent research by Reco has unveiled a persistent data scraping campaign, dubbed the City Forum campaign, that has exploited vulnerabilities in Salesforce and ServiceNow customer portals since 2025. This operation, traced back to a single server (IP address: 158.220.87.79), has successfully extracted records from various organizations across multiple industries. The implications of such extensive data breaches are profound, as they not only compromise sensitive business information but also potentially expose customers' personal data to unauthorized access and misuse.

For businesses utilizing Salesforce and ServiceNow, this incident underscores the critical importance of robust cybersecurity measures and continuous monitoring of their platforms. Organizations must prioritize the implementation of strong authentication protocols, regular security audits, and employee training to mitigate the risk of similar attacks. This case serves as a stark reminder of the evolving landscape of cyber threats, where even well-established platforms are susceptible to coordinated and sophisticated scraping efforts, emphasizing the need for a proactive approach to cybersecurity in the age of AI and digital transformation.

---

*Originally reported by [The Hacker News](https://thehackernews.com/2026/08/one-attacker-has-scraped-both.html)*