Skip to content
Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

Darkreading •Jai Vijayan • August 12, 2026

The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

An unknown threat actor has been using a custom toolset to probe Salesforce and ServiceNow instances with overly permissive guest access and steal data for more than a year.

The targets have spanned multiple sectors, including telecommunications, financial services, enterprise software, security and data-privacy companies, and public-sector portals worldwide. Researchers at AI cybersecurity firm Reco, who are tracking the campaign, have dubbed it "City-Forum" after the domain name linked to the attacker’s IP address, and it's been active since at least March 2025.

What makes the campaign notable, according to Reco, is the extent to which the threat actor appears to have researched the two platforms and then built their own tools to identify data that organizations may have inadvertently left accessible to guest users.

For example, on newer Salesforce sites that use the company's Lightning Web Runtime (LWR) instead of the older Aura framework, the attacker appears to have figured out how to interact directly with the runtime's underlying data-access layer and retrieve records from exposed, guest-accessible surfaces.

Unlike other attackers that have relied on publicly available tools to scan for data accessible through over-permissioned Salesforce guest users via Aura, this actor appears to have developed new techniques for reaching less-documented interfaces like LWR's data-access layer.

The threat actor is using the same custom toolset to similarly target a relatively obscure ServiceNow Service Portal endpoint "that has almost no online documentation or well-known open source tools," Nitay Bachrach, senior security researcher, wrote in a blog post . The attacks suggest the threat actor has mapped multiple, previously unexplored potential data-leak paths across both platforms.

"The threat actor created their own toolset, based on research and techniques which are not well documented online. They studied the services to map different common data leak vectors — this is an advanced actor," Bachrach concluded. Using Salesforce guest access, the attacker could be stealing account data, information, leads, users, and content document files. On ServiceNow, the list of potential exposures includes knowledge bases and catalogs.

On the surface at least, the City-Forum campaign resembles a similar campaign by the ShinyHunters group that targeted Salesforce environments. But the custom tools used differ from what ShinyHunters used in those attacks, Bachrach said.

Bachrach tells Dark Reading that a common example of Salesforce data that attackers have typically retrieved using guest access include customer information such as Social Security numbers, medical data, financial data, credit card numbers, and passport information. Also common are support tickets and their content, and calendar and email data, including internal emails and meetings.

"In ServiceNow, it's mostly Knowledge Base articles. ServiceNow is highly configurable and, therefore, depending on the specific setup, it could expose anything. In the past, independent researchers demonstrated they could find sensitive data in ServiceNow knowledge bases using other techniques," Bachrach says.

Based on a review of customer logs, the threat actor has targeted organizations in North America, Europe, and Asia, he says. The Salesforce campaign appears much larger than the ServiceNow campaign, with more targets being compromised.

The research that the threat actor must have conducted before carrying out these attacks is not as sophisticated as finding a zero-day vulnerability, Bachrach notes. "But it requires the attacker to map potential weak points in a service, simulate them in their own dev instances, and study the traffic," he says. AI can help make such research more accessible to attackers, but it still requires setting up labs and mapping those potential threats.

Reco has provided indicators of compromise tied to the City-Forum campaign as well as specific guidance for hunting these indicators in Salesforce Event Monitoring logs and ServiceNow transaction logs.

In addition, Reco has outlined several measures organizations can take to mitigate the risk from such campaigns. For Salesforce users, the recommendations include reviewing guest-user sharing rules and removing access to records that anonymous users do not need, disabling unnecessary permissions on guest profiles, and turning off self-registration and guest file access where they aren't needed.

For organizations using ServiceNow, Reco recommended removing sources that don't need to be exposed publicly and enforcing appropriate authentication and access controls for each source, including custom scripted sources.

It's important for administrators to keep in mind that successful attack campaigns have involved specific misconfigurations for the two services rather than out-of-the-box setups, Bachrach says. "Seeing an indicator does not mean sensitive data was stolen," he says. "That being said, whether it shows up or not, it's crucial to audit the environment. Audit every Salesforce site and ServiceNow portal."

Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies.

Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders.

Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications.

His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee.

The State of Cloud Security: The Latest Challenges

How Organizations Are Managing Incident Response

How Enterprises Are Developing Secure Applications

Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy

Essential News & Insights from Black Hat USA 2025

The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember

Building a Secure AI Strategy for the Enterprise

Is your AppSec program Mythos Ready?

Experts Explain How to Develop a Framework for Cyber-Fraud Fusion

Prevention at Machine Speed: Hunting Beyond Known Detections

Extracted Entities