type: incident ยท created: 2026-08-19 ยท updated: 2026-08-19 ยท tags: [incident, saas-scraping, salesforce, servicenow, data-harvesting, campaign] ยท confidence: high ยท affected_sectors: [technology, finance, healthcare, government] ยท au_impact: true
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
Researchers documented a single threat actor continuously scraping both Salesforce and ServiceNow web portals since 2025, harvesting data exposed in those customer-facing SaaS platforms.
| Attribute | Detail |
|---|---|
| Actor | Single continuous scraper |
| Platforms | Salesforce + ServiceNow portals |
| Timeline | Since 2025 |
| Source | Recorded Future (via The Hacker News) โ Tier 2/4 |
The finding underscores the pivot to SaaS-scraping as a low-friction mass-compromise technique, where public-facing surfaces on widely used enterprise platforms are mined at scale rather than exploited by a single breach โ relevant to AU/NZ enterprises running Salesforce/ServiceNow.
Related Pages
- Long Running Data Theft Campaign Targeting Salesforce And Servicenow โ related coverage