Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

ServiceNow tells customers a bug left some of their data exposed to the internet

Дата публикации: 10-06-2026 14:13:02

ServiceNow is used by thousands of enterprises to automate their internal processes, but says several customers had data accessed because of a security bug.

Основное содержимое страницы с новостью.

Cloud technology giant ServiceNow has notified some of its enterprise customers that a software bug on its platform was allowing anyone on the internet to access their data.

A knowledge base article, which ServiceNow has hidden behind a login wall but has been shared on Reddit, says the company on June 5 patched some customer instances to fix a bug that had allowed unauthenticated users to “gain greater access” to ServiceNow-hosted data than intended.

The bug allowed potentially anyone to access data stored in customer instances without requiring credentials, such as a password. 

ServiceNow tells TechCrunch that the security incident was not a hack, but the work of security researchers who were looking for vulnerabilities that they could submit for a bug bounty program.

“Alongside our own investigation, we have been in contact with the security researchers who initially reported this issue and can confirm that evidence of the observed activity came from those security researchers and customer research teams, not bad actors,” said ServiceNow spokesperson Courtney Johnson. “The security researchers have advised their activity was solely for bug bounty submissions and no data was used or retained.”

When asked by TechCrunch, ServiceNow did not immediately name the security researchers, nor say how many ServiceNow customers’ data was accessed.

Given that the security incident appears to stem from a data-exposing bug, it’s unclear if customers could have protected themselves from improper access prior to the incident.

ServiceNow is a cloud computing giant that allows thousands of its enterprise customers to automate their internal business processes. Companies use the tech giant’s platform to build workflows that connect to various apps and databases, such as IT and HR systems, which can be used to automatically handle repeat tasks, like onboarding staff, resolving tech support tickets, and for chatbots.

As such, companies like ServiceNow can be high-value targets for hackers thanks to the amount of sensitive data that they store, such as customer support tickets, which can include passwords, keys, and credentials.

ServiceNow said the issue relates to customer instances running its Australia releases, but several people on Reddit say they have identified evidence of external access to ServiceNow instances running other versions of its software.

Network defenders shared an IP address, 51.159.98.241, said to be an indicator of potential data access if found in a customer’s logs.

Corrected the seventh paragraph to update references to the Australia releases, unrelated to geography. Updated to include comment from ServiceNow.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.

He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View Bio

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Password manager maker LastPass says hackers stole customer support case data during Klue breach-2523-06-2026
2Klue says hackers stole credential from 2022 that led to customer data breaches-2623-06-2026
3Klue hack results in data breach at several cybersecurity firms-2722-06-2026
4Facebook сообщила о инциденте с безопасностью, затронувшем почти 50 млн аккаунтов0028-09-2018
5Offene Datenbank: Nextcloud GmbH behebt potenzielles Datenleck0708-07-2026
6CNBC: личные данные некоторых пользователей Amazon по ошибке оказались в открытом доступе0022-11-2018
7Сторонние приложения из-за ошибки получили доступ к фотографиям пользователей Facebook0014-12-2018
8Companies House closed temporarily after glitch allowed people to edit OTHER firms' details-2713-03-2026
9Альфа-банк проводит внутреннее расследование из-за утечки данных клиентов0005-11-2019
10Quora сообщил об утечке личных данных более 100 млн пользователей0004-12-2018

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: -2. Информативность: 5. Источник: techcrunch.com.