Feeds2.Feedburner
City-Forum Campaign Targets Salesforce and ServiceNow Data Exposures
Article Content
The City-Forum campaign has been actively stealing data from Salesforce and ServiceNow portals since March 2025. Researchers at Reco have identified that the threat actor utilizes custom tools to exploit overly permissive guest access configurations. The campaign has targeted various sectors, including telecommunications, financial services, and public-sector organizations globally. The attacks are ongoing, with a notable increase in activity, primarily using a specific IP address linked to a German VPS provider. The threat actor has developed unique techniques to probe both Salesforce's Lightning Web Runtime and ServiceNow's Service Portal, indicating advanced research and mapping of potential data leak paths. No vulnerabilities in the platforms are being exploited; instead, the attacks rely on misconfigurations allowing unauthorized access. The volume of attacks has surged, with one organization recording over 560,000 events from the attacker's IP. The City-Forum campaign resembles previous attacks by ShinyHunters but employs different tools and methodologies.
Key Points: • The City-Forum campaign has been active since March 2025, targeting Salesforce and ServiceNow. • Attackers exploit misconfigured guest access to steal sensitive data from multiple sectors. • The campaign has seen a significant increase in activity, with one target logging over 560,000 events.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.