Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-19 ยท updated: 2026-08-19 ยท tags: [incident, saas-scraping, salesforce, servicenow, data-harvesting, campaign] ยท confidence: high ยท affected_sectors: [technology, finance, healthcare, government] ยท au_impact: true

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

Researchers documented a single threat actor continuously scraping both Salesforce and ServiceNow web portals since 2025, harvesting data exposed in those customer-facing SaaS platforms.

Attribute Detail
Actor Single continuous scraper
Platforms Salesforce + ServiceNow portals
Timeline Since 2025
Source Recorded Future (via The Hacker News) โ€” Tier 2/4

The finding underscores the pivot to SaaS-scraping as a low-friction mass-compromise technique, where public-facing surfaces on widely used enterprise platforms are mined at scale rather than exploited by a single breach โ€” relevant to AU/NZ enterprises running Salesforce/ServiceNow.

Related Pages

Source