{"id":492634,"date":"2026-06-10T15:10:08","date_gmt":"2026-06-10T15:10:08","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/492634\/"},"modified":"2026-06-10T15:10:08","modified_gmt":"2026-06-10T15:10:08","slug":"servicenow-tells-customers-a-bug-left-some-of-their-data-exposed-to-the-internet","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/492634\/","title":{"rendered":"ServiceNow tells customers a bug left some of their data exposed to the internet"},"content":{"rendered":"<p id=\"speakable-summary\" class=\"wp-block-paragraph\">Cloud technology giant ServiceNow appears to have notified some of its enterprise customers that a software bug on its platform was allowing anyone on the internet to access their data.<\/p>\n<p class=\"wp-block-paragraph\">A <a rel=\"nofollow noopener\" href=\"https:\/\/support.servicenow.com\/kb?id=kb_article_view&amp;sysparm_article=KB3067321\" target=\"_blank\">knowledge base article<\/a>, which ServiceNow has hidden behind a login wall but <a rel=\"nofollow noopener\" href=\"https:\/\/old.reddit.com\/r\/servicenow\/comments\/1u0c45c\/potential_servicenow_breach\/oqpciyl\/\" target=\"_blank\">has been shared on Reddit<\/a>, says the company on June 5 patched some customer instances to fix a bug that had allowed unauthenticated users to \u201cgain greater access\u201d to ServiceNow-hosted data than intended.<\/p>\n<p class=\"wp-block-paragraph\">The bug allowed potentially anyone to obtain data stored in customer instances without requiring credentials, such as a password.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s not clear who had improper access to ServiceNow customers, what data was accessed or taken, or if any group was involved. Given that the security incident appears to stem from a data-exposing bug, it\u2019s unclear if customers could have protected themselves from improper access.<\/p>\n<p class=\"wp-block-paragraph\">ServiceNow is a cloud computing giant that allows thousands of its enterprise customers to automate their internal business processes. Companies use the tech giant\u2019s platform to build workflows that connect to various apps and databases, such as IT and HR systems, which can be used to automatically handle repeat tasks, like onboarding staff, resolving tech support tickets, and for chatbots.<\/p>\n<p class=\"wp-block-paragraph\">As such, companies like ServiceNow are high-value targets for hackers thanks to the amount of sensitive data that they store, such as customer support tickets, which can include passwords, keys and credentials.<\/p>\n<p class=\"wp-block-paragraph\">ServiceNow said the issue relates to customer instances running its <a rel=\"nofollow noopener\" href=\"https:\/\/www.servicenow.com\/docs\/r\/release-notes\/family-release-notes.html\" target=\"_blank\">Australia releases<\/a>, but <a rel=\"nofollow noopener\" href=\"https:\/\/old.reddit.com\/r\/servicenow\/comments\/1u0c45c\/potential_servicenow_breach\/oqpciyl\/\" target=\"_blank\">several people on Reddit<\/a> say they have identified evidence of external access to ServiceNow instances running other versions of its software. Network defenders <a rel=\"nofollow noopener\" href=\"https:\/\/old.reddit.com\/r\/servicenow\/comments\/1u0c45c\/potential_servicenow_breach\/oqoo9wj\/\" target=\"_blank\">shared an IP address<\/a>, 51.159.98.241, said to be an indicator of potential compromise if found in a customer\u2019s logs.<\/p>\n<p class=\"wp-block-paragraph\">A spokesperson for ServiceNow did not immediately return TechCrunch\u2019s email requesting comment and seeking answers on how many customers are affected, or how long the bug had exposed the data.<\/p>\n<p class=\"wp-block-paragraph\">Corrected the seventh paragraph to update references to the Australia releases, unrelated to geography.<\/p>\n<p>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" rel=\"nofollow noopener\" target=\"_blank\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/p>\n","protected":false},"excerpt":{"rendered":"Cloud technology giant ServiceNow appears to have notified some of its enterprise customers that a software bug on&hellip;\n","protected":false},"author":2,"featured_media":269119,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[3312,211560,61,60,132074,80],"class_list":["post-492634","post","type-post","status-publish","format-standard","has-post-thumbnail","category-technology","tag-cybersecurity","tag-data-exposure","tag-ie","tag-ireland","tag-servicenow","tag-technology"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/492634","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=492634"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/492634\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/269119"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=492634"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=492634"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=492634"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}