Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-13 ยท updated: 2026-08-13 ยท tags: [incident, saas, salesforce, servicenow, credential-theft, data-breach, campaign] ยท confidence: medium ยท affected_sectors: [technology, finance, government, retail, healthcare] ยท au_impact: true

Long-Running Data Theft Campaign Targeting Salesforce and ServiceNow

Researchers documented a long-running data theft campaign targeting Salesforce and ServiceNow environments โ€” part of the credential-harvesting wave increasingly aimed at SaaS and identity estates rather than networks. No specific victim disclosures are named; the campaign's structure suggests opportunistic exploitation of exposed instances and harvested credentials.

Key Facts

Attribute Detail
Targets Salesforce and ServiceNow environments
Method Credential harvesting, exposed-instance exploitation
Confidence Reported โ€” campaign research; no first-party victim statements
Disclosure date 2026-08-12

Context

Salesforce and ServiceNow sit at the heart of enterprise customer data and IT operations respectively โ€” exactly the systems whose compromise produces the most damaging downstream effects. The campaign aligns with the week's broader theme of attackers targeting the identity and SaaS estate (see Malicious Litellm Releases Tied To Trivy Hack May Have Exposed 2 100 Organisatio). For AU/NZ organisations, the practical controls are MFA on all SaaS admin accounts, monitoring of unusual instance access, and treating SaaS credentials as high-value secrets under Essential Eight identity guidance.

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-13