What Happened: The Salesforce and ServiceNow Exposure

A recent weekly security roundup from Help Net Security flagged one story that deserves more than a passing mention: Salesforce and ServiceNow customer portals were left exposed for roughly 17 months before the issue came to light. The digest, which also covered an exploited Metabase zero-day vulnerability and an expansion of GitHub's Dependabot malware alerts, grouped these items together for a reason. Each one illustrates a different flavor of the same underlying problem: enterprise software platforms, whether self-hosted analytics tools, code repositories, or cloud CRM systems, are only as secure as the configurations and vendor practices behind them.

Salesforce and ServiceNow are two of the most widely used platforms for managing customer relationships, support tickets, and internal workflows across large organizations. When portals built on these platforms are exposed, the fallout is not limited to the company running them. Depending on how the portal was configured and what data it stored, exposure can reach customer names, contact details, support histories, and other records that individuals never directly handed over to the company that leaked them. That is the core tension in enterprise data breach exposure cases: the person whose data is at risk often has no direct account or credentials with the platform involved. They are exposed simply because a business they interacted with chose that platform to store information.

Why a 17-Month Discovery Lag Matters for Consumer Privacy

The most striking detail in this story is not the exposure itself, it is the duration. Seventeen months is a long time for a misconfigured or vulnerable portal to sit accessible without detection. During that stretch, any data sitting in the exposed system could have been viewed, scraped, or copied by anyone who found it, and there would be little way for the affected organization to know for certain what was accessed versus what was merely accessible.

This gap between exposure and discovery is a recurring theme in enterprise security failures, and it matters enormously for consumer privacy. A breach discovered within days can be contained relatively quickly: credentials reset, access revoked, affected parties notified. A breach that lingers for over a year gives attackers, scrapers, and opportunists a much longer window, and it makes forensic reconstruction far harder. Security teams often cannot say with confidence how many times the data was accessed or by whom, only that the door was left open for a long time. For anyone whose information passed through one of these portals, that uncertainty is the real cost.

Third-Party and Supply-Chain Risk Keeps Surfacing in CRM Platforms

This is not an isolated pattern. CRM and support-platform exposures keep surfacing precisely because so many organizations route sensitive customer data through the same handful of third-party systems. When something goes wrong at that layer, it rarely affects just one company; it ripples outward to every business that relied on the same platform, integration, or vendor relationship.

A clear recent example of this dynamic is the LastPass supply chain breach via Klue, where attackers compromised a third-party vendor and used stolen OAuth tokens to reach into LastPass's own Salesforce environment. That incident and the 17-month Salesforce/ServiceNow exposure both point to the same structural issue: enterprise CRM platforms sit at the intersection of many companies' data flows, and a single weak link, whether a misconfiguration, an unpatched vulnerability, or a compromised vendor integration, can expose information far beyond the organization that owns the portal.

What This Means for You

If you have ever submitted a support ticket, filled out a contact form, or interacted with customer service at a company that uses Salesforce, ServiceNow, or similar platforms, some of your information likely lives in a system you never directly logged into. That means you are dependent on that company's vendor choices and security practices, not just your own habits, to keep your data safe.

A VPN will not protect you from this kind of exposure. VPNs secure your own connection and browsing activity; they do nothing to shield data sitting on a company's backend CRM system. The realistic defenses here are different: watch for breach notifications from companies you do business with, use unique passwords for every account so a leak in one place cannot be leveraged elsewhere, and enable multi-factor authentication wherever it is offered. These habits will not prevent an enterprise-side leak, but they sharply limit what an attacker can do with any data that does get exposed.

Actionable Takeaways

  • Treat breach notifications from service providers seriously, even if you do not recall directly creating an account with the affected platform.
  • Use a password manager to keep credentials unique across services, reducing the blast radius of any single enterprise data breach exposure.
  • Enable multi-factor authentication on accounts tied to companies that store your personal or financial data.
  • Periodically review which companies and portals you have shared information with, and consider requesting data deletion where it is no longer needed.

Stories like this 17-month Salesforce and ServiceNow exposure are a reminder that enterprise data breach exposure is often invisible to the people it affects until long after the fact. Staying informed about how these incidents unfold, and tightening your own account hygiene in response, remains the most practical way to limit the damage when the next one surfaces.