Long-Running Data Theft Campaign Targeting Salesforce and ServiceNow
Researchers documented a long-running data theft campaign targeting Salesforce and ServiceNow environments โ part of the credential-harvesting wave increasingly aimed at SaaS and identity estates rather than networks. No specific victim disclosures are named; the campaign's structure suggests opportunistic exploitation of exposed instances and harvested credentials.
Key Facts
| Attribute | Detail |
|---|---|
| Targets | Salesforce and ServiceNow environments |
| Method | Credential harvesting, exposed-instance exploitation |
| Confidence | Reported โ campaign research; no first-party victim statements |
| Disclosure date | 2026-08-12 |
Context
Salesforce and ServiceNow sit at the heart of enterprise customer data and IT operations respectively โ exactly the systems whose compromise produces the most damaging downstream effects. The campaign aligns with the week's broader theme of attackers targeting the identity and SaaS estate (see Malicious Litellm Releases Tied To Trivy Hack May Have Exposed 2 100 Organisatio). For AU/NZ organisations, the practical controls are MFA on all SaaS admin accounts, monitoring of unusual instance access, and treating SaaS credentials as high-value secrets under Essential Eight identity guidance.
Related Pages
- Malicious Litellm Releases Tied To Trivy Hack May Have Exposed 2 100 Organisatio โ AI gateway credential theft
- 737 Chrome Vpn Extensions Caught Routing Traffic Through Single Proxy Infrastruc โ extension supply-chain abuse
Sources: raw/digests/Cyber-Digest-2026-08-13