ServiceNow Ticket Data May Have Exposed Standing Secrets
An exposed ServiceNow API turns support records into a trust break, not just a data leak. If attackers could query instance tables without authentication, they may have pulled tickets, notes, and internal records that hold passwords, API tokens, and other secrets that still work after the portal is fixed.
ServiceNow says attackers exploited the flaw to query customer instance tables and that it applied a security update to hosted instances on June 5, 2026. The update changed the API so only authenticated users can access it, but the company has not disclosed what data was taken; support cases often carry the exact secrets teams share during troubleshooting.
That means the risk can extend into other accounts and services that trusted those records. A patched SaaS portal does not undo credentials or tokens already lifted from helpdesk data.