Observed Signal · Jun 10, 2026 · Security Incident · Source: techcrunch · Impact: 3/5 · Sentiment: Negative

ServiceNow Bug Exposed Customer Data

Executive Signal Summary

ServiceNow notified some enterprise customers that a software bug on its platform allowed unauthenticated users to access data stored in customer instances. According to a company knowledge-base article (shared publicly via Reddit), ServiceNow patched affected customer instances on June 5. ServiceNow said the issue related to Australian customer instances, but multiple Reddit users reported evidence of external access to instances outside Australia; an IP address (51.159.98.241) was shared as a potential indicator of compromise. It remains unclear how many customers were affected, which records (if any) were accessed or exfiltrated, and who — if anyone — exploited the bug. TechCrunch sought comment from ServiceNow but had not received an immediate response at the time of reporting.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

A data-exposing bug in a major enterprise SaaS platform risks exposure of sensitive customer records and creates supply-chain/security risk for many businesses that rely on ServiceNow for IT and workflow automation.

SIGNAL RADAR

Track ServiceNow Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • ServiceNow notified some enterprise customers that a software bug allowed greater-than-intended access to ServiceNow-hosted data.
  • ServiceNow patched affected customer instances on June 5, 2026, per a company knowledge-base article.
  • ServiceNow said the issue related to Australian customer instances, but third-party reports indicate instances outside Australia may show evidence of external access.
  • Reddit users and network defenders shared an IP address (51.159.98.241) as a potential indicator of compromise.
  • It is unknown how many customers were affected, what specific data (if any) was accessed or exfiltrated, or who was responsible.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: techcrunch•Published: Jun 10, 2026
Original Coverage Title: “ServiceNow tells customers a bug left some of their data exposed to the internet”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Market Research & Consumer Panel (data breach at market intelligence provider)Jun 22, 2026

Klue hack exposes customer data across cybersecurity firms

Market intelligence provider Klue disclosed a cyberattack that allowed hackers to exfiltrate customer data from connected cloud systems. Klue said intruders gained access on June 12 using a “compromised legacy credential” tied to an integration tool that links customers’ cloud data (such as Salesforce) to Klue. The cybercrime group Icarus claimed responsibility and threatened to publish the stolen data if a ransom is not paid. Multiple Klue customers — including Gong, Jamf, HackerOne, OneTrust, Recorded Future, Snyk, Sprout Social, Tanium, Insurity and Huntress — have confirmed data theft of business contact and some account information. Klue engaged CrowdStrike for incident response and disconnected integrations to block further access. The company has not disclosed how many customers were affected or how the credentials were obtained.

Read assessment
PrivacyApr 16, 2026

Express Left Customer Data Exposed Online

Fashion retailer Express patched a security flaw after researcher Rey Bango discovered that order confirmation pages on the company's online store were accessible by changing sequential order numbers in the URL. At least a dozen customer orders were indexed in web search results, exposing names, phone numbers, emails, postal/billing/delivery addresses, purchased items, and partial payment card details (card type and last four digits). TechCrunch verified the URL-based enumeration and reported the issue to Express, which fixed the vulnerability but declined to say whether it will notify affected customers or state attorneys general. Express is owned by WHP Global. The incident adds to recent cases of customer data exposure caused by misconfigurations and inadvertent lapses at large retailers and service providers.

Read assessment
PrivacyJul 16, 2026

Booking.com Reservation Data Exposed via Vendor Breach

Booking.com confirmed that unauthorized third parties accessed reservation data for a subset of customers after a third-party service in its booking workflow was compromised. Exposed fields reportedly included full names, postal addresses, booking dates, email addresses, and phone numbers. Booking.com said its core platform was not compromised. The article frames this incident as an example of vendor-chain/supply-chain risk and recommends vendor-chain pentesting steps — vendor enumeration, trust simulation, token scope audits, signature/origin validation, and an incident playbook — to reduce future exposure.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.