A single attacker has been quietly pulling records from Salesforce and ServiceNow customer portals since 2025 – across multiple industries, for over a year, before anyone published a detailed account of the activity. That’s the finding from agent security platform Reco, and it should stop every RevOps leader in their tracks. Not because CRM platforms are inherently broken, but because most go-to-market teams have quietly assumed their customer data is safer than it is.
The timing is awkward. The GTM world is accelerating hard into agentic tools, AI-assisted outreach, and automated pipeline workflows. Boom, a leasing operating system for single-family rentals, just raised $15 million in Series A funding and simultaneously launched BoomCRM – an agentic leasing and touring CRM product. That’s one data point, but it reflects a broader pattern: vertical-specific CRMs with AI agents built in are arriving fast, and they’re connecting to more customer records than legacy tools ever did.
The Hidden Cost of a Disconnected Stack
HubSpot’s recent analysis of sales collaboration tools makes a blunt observation: sales teams running lean stacks close deals faster than teams drowning in disconnected tools. Not a new idea, but the security dimension of stack bloat is underappreciated. Every integration point is a potential exposure vector, and every third-party connector touching your CRM is another surface the Reco-documented attacker could have exploited.
Most revenue teams think about their sales pipeline in terms of coverage and velocity. Fair enough – those things drive the number. But pipeline integrity also depends on the data inside it being trustworthy. If prospect and customer records are being quietly scraped, your sales forecast is built on compromised information. Your competitive positioning could be leaking. Your Ideal Customer Profile data – arguably the most strategically sensitive asset a GTM team owns – is sitting in portals that an attacker has already accessed elsewhere.
The fix isn’t to stop using CRM tools. It’s to treat stack decisions as security decisions, not just productivity decisions.
How Target Account Selling Changes Your Exposure Profile
There’s a practical GTM reason to care about this beyond the obvious compliance angle. Target account selling – focusing resources on a defined set of high-fit accounts rather than broad outbound spray – is gaining traction precisely because it concentrates effort and improves win rate. The tradeoff is that you’re also concentrating your most sensitive data. Your top 50 target accounts, enriched with firmographic data, buying signals, and stakeholder maps, represent enormous intelligence value – for you and for anyone who can access it without authorisation.
A leaner, more deliberate approach to account targeting means you need to be equally deliberate about where that data lives, who can access it, and what your audit trail looks like. Practically, that means:
- Auditing which external portals and self-service hubs are connected to your CRM instance right now
- Restricting API access to integrations that are actively used – not just historically approved
- Reviewing guest and partner portal permissions, which were the specific attack surface identified in the Reco research
- Setting up anomaly alerts for bulk record access, especially from unfamiliar IP ranges
None of that is exotic. It’s table stakes that a surprising number of GTM teams skip because security feels like an IT problem, not a revenue problem. It’s both.
Building Pipeline Without Building Risk
The broader GTM lesson here is about intentionality in tool selection. Vertical CRMs like BoomCRM are worth watching because they’re purpose-built for specific workflows – in Boom’s case, leasing and touring in single-family rentals. Purpose-built tools often have smaller attack surfaces than general-purpose platforms stuffed with integrations, simply because they do less. That’s a real architectural advantage, not just a marketing angle.
For horizontal GTM teams, the equivalent is discipline. You don’t need every enrichment tool, every intent data feed, and every conversation intelligence platform running simultaneously and connected to your core CRM. Pick the integrations that actually move your sales cycle and cut the rest. Your Customer Acquisition Cost won’t thank you for the tool sprawl anyway.
The Pony AI story – robotaxi revenue hitting 33% of total quarterly revenue – is an interesting parallel. Autonomous systems generating meaningful revenue at scale require a level of operational trust that only comes from rigorous data integrity. Revenue teams are heading in a similar direction, with AI agents increasingly handling prospecting, follow-up, and scheduling. Those agents need clean, secure, reliable data to operate. If the underlying CRM data is compromised, the agent output is too.
What Revenue Teams Should Do This Quarter
Security audits of GTM infrastructure rarely make it onto the quarterly planning agenda. They should. Here’s what a practical response looks like for a revenue team – not an IT team – in the next 90 days.
First, map your data. Know exactly which customer and prospect records live where, which portals expose them, and which integrations touch them. This is a RevOps task, not just an IT task, because RevOps owns the stack decisions that created the exposure in the first place.
Second, tighten your ICP and target account data handling. The more valuable the data, the more carefully it needs to be segmented and permissioned. Your named accounts list shouldn’t be accessible to every portal user or every integration you approved eighteen months ago and forgot about.
Third, check your Net Revenue Retention assumptions. If customer data has been compromised, you may see downstream effects in account behaviour – competitors showing up with unusually specific knowledge, deals going sideways for reasons that don’t quite add up. It’s worth correlating any anomalies with the timeline Reco identified.
The bottom line: a leaner GTM stack is a more defensible one. Start there. Review your connected tools against our CRM Tools Directory, cut the integrations you’re not actively using, and treat your target account data with the same care you’d give your financial records. Because at this point, that data is just as valuable – and apparently just as exposed.
