Your personal info, even if you’ve never touched Salesforce or ServiceNow, might just have been exposed by a sneaky new cyberattack. Cybercriminals are using clever, custom-made tools to swipe sensitive information from online customer portals built using Salesforce Experience Cloud and ServiceNow. These aren't direct attacks on Salesforce or ServiceNow themselves, but rather on the specific "front doors" that companies set up for customers to log in and manage their accounts.
Think of it like this: Salesforce and ServiceNow provide the sturdy building materials and blueprints for a bank (the underlying software platform). Companies then use these to build their own specific branch locations (your customer portal). This attack isn't about blowing up the whole bank, but rather about finding unlocked side doors or windows in individual branches that the companies themselves built, allowing anonymous access to customer data. The criminals are specifically targeting data that’s accidentally left visible to anyone, even those who aren't logged in.
Why does this matter? Many companies, from your phone provider to your healthcare insurer, use Salesforce or ServiceNow to manage customer interactions. If one of these companies accidentally configured their portal incorrectly, allowing unauthenticated users to see information that should be private, this new attack method could scoop it right up. The stolen data could include anything from names and contact details to more sensitive information, depending on what the specific company exposed.
This ongoing campaign, dubbed "City-Forum," highlights a persistent problem in the tech world: even with robust underlying platforms, human error in configuration can open doors for attackers. It’s a reminder that security isn't just about the strength of the lock, but also about making sure all the windows are properly closed and latched. This isn't about a flaw in Salesforce or ServiceNow’s core security, but rather how companies implement and manage their portals.
While there’s no specific action you can take to prevent this particular type of data theft, it’s a good moment to double-check your security hygiene. Make sure you’re using unique, strong passwords for every online account, and enable two-factor authentication (where you get a code to your phone or email) whenever possible. This won’t stop data from being stolen from a company's database, but it will make it much harder for criminals to then use that stolen data to access your accounts.
Companies need to ensure their customer portals are configured correctly to prevent unauthorized data exposure.