ZeroHour
Organization

ServiceNow

2 mentions in 7 days · 2 in 30 days · 3 total · first seen · last

Timeline

Microsoft sees some new wrinkles in invoice-scam emails

Microsoft researchers observed a BEC invoice scam sending 1M+ AI-assisted emails impersonating executives and ServiceNow to request ~$50,000 payments.

Microsoft researchers tracked a campaign of more than one million invoice-scam emails launched in early August, with about 88% of targets in the United States. Attackers impersonated top executives and ServiceNow, fabricating forwarded email threads and invoices to convince accounts payable teams to send payments of nearly $50,000. Microsoft found indicators such as extensive HTML comments and highly uniform template construction consistent with AI-assisted campaign development, though it could not independently establish how much content AI generated.

The Record · 4d agoPhishing & fraud

Hackers Impersonate CEOs in 1 Million Emails to Trick Employees Into $50,000 Payments

A BEC campaign sent over one million fake CEO invoice emails, mostly to US firms, urging ~$50,000 ACH transfers to attacker accounts.

Microsoft analysts tracked a business email compromise campaign that sent more than one million messages between August 3 and 5, with 87.7% targeting US recipients. Emails impersonated CEOs, CFOs, and presidents and carried fake ServiceNow-branded subscription invoices directing accounts-payable staff to make ACH transfers of nearly $50,000 to attacker-controlled accounts. No malicious attachments or malware were used, and researchers observed signs consistent with AI-assisted template development. Lookalike domains such as service-nowinc[.]com and third-party delivery accounts were used, while named firms like ServiceNow showed no evidence of compromise.

Cyber Security News · 4d agoPhishing & fraud 2 sources1

A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months

Reco tracks City-Forum, an actor abusing Salesforce and ServiceNow guest-user access from one IP for 17 months to enumerate portal data.

Reco's City-Forum investigation found one IP address, tied to a dormant 2002 domain, anonymously enumerating Salesforce Experience Cloud and ServiceNow portals across telecoms, banks, enterprise software vendors, and public sector since at least March 2025. No vulnerability was exploited and no credentials were used; the actor abused over-permissioned guest users, including a previously undocumented ServiceNow portal search endpoint, with the busiest single target logging over 560,000 events. Audit logs show what was requested but not which records or fields were returned, so defenders must replay anonymous requests to assess exposure.

Help Net Security · Aug 12, 2026Threat actor