City-Forum Campaign Targets Salesforce and ServiceNow Portals Globally

City-Forum Campaign Targets Salesforce and ServiceNow Portals Globally

First seen 12 Aug 2026, 19:07 UTC Feeds2.FeedburnerCybersecuritynews 71% similarity 66.5

Article Content

Browse articles
ThreatCluster

The City-Forum Campaign has been actively siphoning data from Salesforce and ServiceNow portals for 17 months. Researchers at Reco identified the threat actor, who is exploiting guest user access to pull records from various sectors, including telecommunications and banking. The campaign is ongoing, with no signs of cessation. Affected organizations include financial services firms and public-sector portals. The attack leverages legitimate access methods, raising concerns about security configurations. The exact number of compromised records remains unclear, but the scale is significant. This operation highlights vulnerabilities in widely used enterprise platforms. Current status indicates continued data extraction without detection.

Key Points: • The City-Forum Campaign has been active for 17 months, targeting Salesforce and ServiceNow. • Data is being siphoned from various sectors, including banks and telecommunications. • The attack exploits guest user access, indicating potential security configuration issues.

ThreatCluster AI How this analysis works

Timeline

2025-03-01
City-Forum Campaign identified
Researchers at Reco began tracking the City-Forum Campaign targeting Salesforce and ServiceNow portals.
Feeds2.Feedburner
2025-08-12
Data siphoning confirmed
The campaign was confirmed to be extracting data from multiple sectors, including financial services.
Cybersecuritynews
Recent
Ongoing data extraction
The City-Forum Campaign continues to operate, with no signs of stopping or being detected.
Cybersecuritynews

Community

Browse all →