Act
active
Attacker Scraping Salesforce and ServiceNow Portals Since 2025
- Engineer — Plan: Salesforce and ServiceNow are near-universal in enterprise estates; audit portal access logs for IP 158.220.87.79 going back to early 2025, and review guest-user permissions and external sharing rules on both platforms.
- SOC/IR — Act: A confirmed, long-running campaign with a published IOC (158.220.87.79) hitting widely deployed enterprise SaaS — sweep Salesforce and ServiceNow access logs in your SIEM for that IP since January 2025 and build a persistent detection for it.
- Leader — Act: Active multi-industry data-scraping of Salesforce and ServiceNow portals lasting over a year raises potential customer-data exposure; confirm whether your organization’s portals were targeted and assess notification obligations before customers ask.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.