Cloud technology giant ServiceNow appears to have notified some business customers that a bug in the software on its platform has made their data accessible to anyone on the internet.
ServiceNow hides behind a login wall, but on June 5, the company patched some customer instances to fix a bug that allowed unauthenticated users “greater access” to data hosted on ServiceNow than intended, according to a knowledge base article shared on Reddit.
This bug could potentially allow anyone to retrieve data stored on a customer instance without requiring credentials such as a password.
It is not clear who gained unauthorized access to ServiceNow customers, what data was accessed or obtained, or whether any groups were involved. Given that this security incident appears to have been caused by a data leak bug, it is unclear whether customers were able to protect themselves from unauthorized access.
ServiceNow is a cloud computing giant that enables thousands of enterprise customers to automate internal business processes. Companies can use the tech giant's platform to build workflows that connect to various apps and databases, such as IT and HR systems, and can be used to automatically handle repetitive tasks such as onboarding staff, resolving technical support tickets, and chatbots.
This makes companies like ServiceNow valuable targets for hackers, as they store large amounts of sensitive data such as customer support tickets containing passwords, keys, and credentials.
ServiceNow said the issue was related to customer instances in Australia, but several people on Reddit who are not located in Australia said they had identified evidence of external access to their ServiceNow instances. Network Defender shared IP address 51.159.98.241. This address is said to be an indicator of a possible compromise if found in customer logs.
A ServiceNow spokesperson did not immediately respond to an email from TechCrunch seeking comment on how many customers were affected or how long the bug exposed data.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

