GetSOC2

A year-long campaign is quietly draining Salesforce and ServiceNow tenants

August 18, 2026. From issue 2 of The Compliance Brief, one story for companies buying a SOC 2 audit.

Last reviewed 2026-08-18Written by Jacob Masse, TrazTech Inc.

Issue 2 of The Compliance Brief went to subscribers on August 18, 2026. One of its 5 stories bears on SOC 2 audits, auditors and vendor reviews, and they are below in short form. The full issue, with every take in full, is on traztech.ca.

Source: Dark Reading

Dark Reading reports on a campaign tracked as City-Forum, active since at least March 2025, that has been stealing data from Salesforce and ServiceNow tenants using custom tooling. Targets span multiple sectors.

Our take, in short

Most SOC 2 scopes I read draw a boundary around the product and leave the CRM outside it, which is a fiction, because the CRM holds contract terms, support tickets with customer data pasted in, and often production credentials someone shared in a case comment. The attack path here is rarely the platform itself, it is a third-party app with...

Read the full take on traztech.ca

Also in issue 2

Outside SOC 2 audits, auditors and vendor reviews, but in the same email:

Older: issue 1 All issues on GetSOC2 Newer: issue 3