The Campaign That Went Unnoticed for 17 Months
Salesforce and ServiceNow are business software platforms used by thousands of companies to manage customer records, support tickets, and internal workflows. According to Help Net Security, researchers at security firm Reco uncovered a campaign — dubbed City-Forum — where an unknown party spent 17 months siphoning records from these portals worldwide.
What makes this story unusual is that nothing was broken into. The portals functioned exactly as designed. The attacker appeared to operate through a domain registered back in 2002, since abandoned, now pointing to a rented server in Germany. From there, someone was methodically pulling records out of corporate portals, one query at a time.
Think of it like a janitor who was never removed from the building's keycard system. No alarms, no broken locks — just access that should have been revoked long ago.
The same week, Framework — the company behind repairable, upgradeable laptops — confirmed attackers exploited a zero-day vulnerability (a flaw with no patch available at the time of attack) in Metabase, a business intelligence tool used to analyse data. Customer names, email addresses, phone numbers, physical addresses, and login IP addresses were accessed. Payment details were not.
What you should do: If you use Salesforce or ServiceNow at work, ask your IT team when user access was last audited. Old accounts with lingering access are a common and overlooked entry point.
Sources

