Salesforce and ServiceNow portals stolen data in ongoing attacks
Attackers are stealing data from public-facing Salesforce and ServiceNow portals by tricking users into visiting fake links. The stolen data includes customer information exposed in these portals.
- Report priority
- Medium
- Involves
- Salesforce Experience Cloud
What is known
- Attackers send fake links that trick users into visiting a malicious site.
- The site then steals data from the Salesforce Experience Cloud and ServiceNow customer portals that the user has access.
What to do
Check if you use Salesforce Experience Cloud or ServiceNow customer portals and recently clicked any unexpected links.
Do not click links from unknown senders. If you suspect you've been tricked, log into your portal immediately and check for unusual activity.
Reported details
A user gets an email or message with a link claiming to be from a trusted company. When they click it, they're taken to a fake login page that looks real. If they enter their credentials, the attackers grab any public customer data they can see in their Salesforce or ServiceNow portal. The stolen data includes things like contact details and support tickets.
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals.