Single Attacker Scrapes Salesforce and ServiceNow Portals Since 2025
Reco identifies sustained campaign targeting enterprise CRM and ITSM platforms via one IP infrastructure

Key Takeaways
- A sustained scraping campaign named 'City Forum' has targeted Salesforce and ServiceNow portals since at least 2025.
- Activity is traced to a single IP address: 158.220.87.79.
- The exact access method and specific victim data remain unconfirmed and under investigation.
- Organizations should review portal access controls, API permissions, and monitor for unusual API activity.
Quick answers
- What happened?
- Research published by the agent security platform Reco identifies a sustained scraping campaign, dubbed 'City Forum,' targeting Salesforce and ServiceNow customer portals across multiple industries. The activity is traced to a single IP address, 158.220.87.79, with reports indicating the operation has been active since at least 2025. The exact method of access and specific victim data remain under investigation.
- Which products are affected?
- Salesforce portals, ServiceNow portals
- What should defenders do?
- Review portal access controls and API permissions. Monitor for unusual API activity. Implement rate limiting and anomaly detection for portal access.
According to research published this week by the agent security platform Reco, a single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year. The activity, which Reco has named the City Forum campaign after a domain tied to the attacker's IP address, traces back to one server: 158.220.87.79. The full scope of extracted data, specific victim organizations, and the precise method of unauthorized access have not been disclosed. Reco notes that the campaign's longevity and single-infrastructure focus suggest a deliberate, ongoing effort to harvest data from enterprise CRM and ITSM platforms. The report recommends that organizations review portal access controls, API permissions, and monitor for unusual API activity.
Security Details
Activity traced to IP 158.220.87.79; campaign named City Forum. Method of unauthorized access not specified in available sources. Operation active since at least 2025.
Affected products
Salesforce portals, ServiceNow portals
Mitigation
Review portal access controls and API permissions. Monitor for unusual API activity. Implement rate limiting and anomaly detection for portal access.
Sources
The Hacker News
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
Aug 18, 2026 · 11:30
Original link
Related Security News

Former US Air Force Members Sentenced to Prison for Business Email Compromise Scams
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. The sentencing, reported by BleepingComputer in September 2026, concluded a federal case targeting individuals who abused their military backgrounds to conduct financially motivated email fraud. The attacks spanned multiple years prior to sentencing, though specific victim counts and total financial losses were not detailed in the reporting. The case underscores the legal consequences of using military credentials and training for cyber-enabled fraud.




