A highly skilled attacker has been quietly compromising both Salesforce and ServiceNow portals since 2025, exploiting vulnerabilities in these popular cloud platforms to gain unauthorized access to sensitive customer data. The brazen cyber campaign, which has flown under the radar for over a year, raises serious concerns about the security posture of companies that rely on these platforms.
The attacker, who is believed to be highly sophisticated and well-resourced, has been exploiting cross-domain privilege escalation vulnerabilities in both Salesforce and ServiceNow portals. These vulnerabilities allow an attacker to move laterally across different domains within the portal, essentially giving them free rein to access sensitive data without being detected. By mapping these breach routes at key choke points, the attacker is able to identify and exploit vulnerabilities that would otherwise be difficult to detect.
One of the most alarming aspects of this campaign is its scope and sophistication. The attacker has been targeting a wide range of customers across multiple industries, including finance, healthcare, and technology. According to sources close to the investigation, the attacker has compromised sensitive data belonging to thousands of companies, including customer names, email addresses, and financial information.
The fact that this campaign has gone undetected for so long is a stark reminder of the growing threat posed by sophisticated attackers who are willing to invest significant resources into compromising cloud-based platforms. While both Salesforce and ServiceNow have robust security measures in place, it appears that these vulnerabilities were not adequately addressed in their respective systems.
The implications of this campaign are far-reaching and could potentially expose companies to significant reputational damage, financial losses, and regulatory penalties. It is essential for companies that rely on cloud-based platforms like Salesforce and ServiceNow to conduct thorough risk assessments and implement robust security measures to mitigate these types of vulnerabilities.
For individual users, the key takeaway from this story is to remain vigilant about password management and to exercise caution when accessing sensitive information online. Companies can take proactive steps by implementing multi-factor authentication, conducting regular security audits, and educating their employees on best practices for securing cloud-based applications.
Source: The Hacker News — 2026-08-18