CybersecurityAugust 13, 2026· via BleepingComputer

Hackers exploit Salesforce and ServiceNow portals in city forum data thefts

Hackers exploit Salesforce and ServiceNow portals in city forum data thefts

Image : BleepingComputer

Hackers are quietly siphoning sensitive information from public-facing portals built on Salesforce Experience Cloud and ServiceNow, turning municipal services and community forums into unwitting data mines. The ongoing campaign uses bespoke tools to lift data that should remain private but is mistakenly exposed to anonymous web users, researchers warn. No single breach is being singled out; instead, attackers are probing widely used customer-portal platforms that municipalities and agencies rely on for citizen interactions.

A blind spot in the cloud

The attack vector hinges on configuration oversights rather than software flaws. Portals configured to allow “anonymous” or “guest” access can inadvertently expose records—customer cases, forum posts, or service requests—that contain personal details. Once such data is publicly accessible, malicious actors scrape it with automated scripts and exfiltrate it before administrators notice. Because the portals are legitimate parts of widely trusted platforms, the traffic blends in with normal user activity, making detection difficult.

Why public services are in the crosshairs

City forums and municipal service desks often use these portals for low-friction citizen engagement. When configuration errors open a window, attackers harvest names, email addresses, case notes, and sometimes payment references. The stolen data is then packaged for resale or used in follow-on phishing campaigns aimed at citizens who recently interacted with the service. Unlike headline-grabbing ransomware, this style of theft is stealthy and continuous, with no ransom note to flag the compromise.

Why it matters

This campaign highlights a growing risk in the shift toward cloud-based citizen services: even trusted platforms can leak data if access controls are misconfigured. For local governments and agencies, the lesson is clear—regular security reviews of portal settings and guest-access policies are no longer optional. Citizens, meanwhile, should assume that any data shared with a public portal could eventually appear elsewhere. The breach isn’t in the code; it’s in the oversight, and that’s a harder problem to fix.


Source: BleepingComputer. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on BleepingComputer →

← Back to home