CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 13, 2026

Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

Dark Reading Archived Aug 13, 2026 ✓ Full text saved

The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

Full text archived locally
✦ AI Summary · Claude Sonnet


    CYBERATTACKS & DATA BREACHES CYBER RISK VULNERABILITIES & THREATS THREAT INTELLIGENCE NEWS Long-running Data Theft Campaign Targeting Salesforce, ServiceNow The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling. Jai Vijayan,Contributing Writer August 12, 2026 4 Min Read SOURCE: MIKKELWILLIAM VIA GETTY IMAGES An unknown threat actor has been using a custom toolset to probe Salesforce and ServiceNow instances with overly permissive guest access and steal data for more than a year. The targets have spanned multiple sectors, including telecommunications, financial services, enterprise software, security and data-privacy companies, and public-sector portals worldwide. Researchers at AI cybersecurity firm Reco, who are tracking the campaign, have dubbed it "City-Forum" after the domain name linked to the attacker’s IP address, and it's been active since at least March 2025. A Notably Different Data Theft Approach What makes the campaign notable, according to Reco, is the extent to which the threat actor appears to have researched the two platforms and then built their own tools to identify data that organizations may have inadvertently left accessible to guest users. For example, on newer Salesforce sites that use the company's Lightning Web Runtime (LWR) instead of the older Aura framework, the attacker appears to have figured out how to interact directly with the runtime's underlying data-access layer and retrieve records from exposed, guest-accessible surfaces. Related:Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition Unlike other attackers that have relied on publicly available tools to scan for data accessible through over-permissioned Salesforce guest users via Aura, this actor appears to have developed new techniques for reaching less-documented interfaces like LWR's data-access layer. The threat actor is using the same custom toolset to similarly target a relatively obscure ServiceNow Service Portal search endpoint "that has almost no online documentation or well-known open source tools," Nitay Bachrach, senior security researcher, wrote in a blog post. The attacks suggest the threat actor has mapped multiple, previously unexplored potential data-leak paths across both platforms. "The threat actor created their own toolset, based on research and techniques which are not well documented online. They studied the services to map different common data leak vectors — this is an advanced actor," Bachrach concluded. Using Salesforce guest access, the attacker could be stealing account data, contact information, leads, users, and content document files. On ServiceNow, the list of potential exposures includes knowledge bases and catalogs. On the surface at least, the City-Forum campaign resembles a similar campaign by the ShinyHunters group that targeted Salesforce environments. But the custom tools used differ from what ShinyHunters used in those attacks, Bachrach said. Related:Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA City-Forum's Potentially Wide Exposure Bachrach tells Dark Reading that a common example of Salesforce data that attackers have typically retrieved using guest access include customer information such as Social Security numbers, medical data, financial data, credit card numbers, and passport information. Also common are support tickets and their content, and calendar and email data, including internal emails and meetings. "In ServiceNow, it's mostly Knowledge Base articles. ServiceNow is highly configurable and, therefore, depending on the specific setup, it could expose anything. In the past, independent researchers demonstrated they could find sensitive data in ServiceNow knowledge bases using other techniques," Bachrach says. Based on a review of customer logs, the threat actor has targeted organizations in North America, Europe, and Asia, he says. The Salesforce campaign appears much larger than the ServiceNow campaign, with more targets being compromised. The research that the threat actor must have conducted before carrying out these attacks is not as sophisticated as finding a zero-day vulnerability, Bachrach notes. "But it requires the attacker to map potential weak points in a service, simulate them in their own dev instances, and study the traffic," he says. AI can help make such research more accessible to attackers, but it still requires setting up labs and mapping those potential threats. Related:The Coordination Gap: How Attackers Are Outpacing Law Enforcement Reco has provided indicators of compromise tied to the City-Forum campaign as well as specific guidance for hunting these indicators in Salesforce Event Monitoring logs and ServiceNow transaction logs. In addition, Reco has outlined several measures organizations can take to mitigate the risk from such campaigns. For Salesforce users, the recommendations include reviewing guest-user sharing rules and removing access to records that anonymous users do not need, disabling unnecessary permissions on guest profiles, and turning off self-registration and guest file access where they aren't needed. For organizations using ServiceNow, Reco recommended removing search sources that don't need to be exposed publicly and enforcing appropriate authentication and access controls for each search source, including custom scripted sources. It's important for administrators to keep in mind that successful attack campaigns have involved specific misconfigurations for the two services rather than out-of-the-box setups, Bachrach says. "Seeing an indicator does not mean sensitive data was stolen," he says. "That being said, whether it shows up or not, it's crucial to audit the environment. Audit every Salesforce site and ServiceNow portal." About the Author Jai Vijayan Contributing Writer Illinois-based Jai Vijayan is a veteran, award-winning technology journalist with more than 25 years of experience covering cybersecurity. His information security reporting has explored everything from ransomware, nation-state threats, and identity security to AI risk, critical infrastructure protection, software supply chain security, cloud security and emerging enterprise technologies. Over the course of his career, Jai has written news stories, feature articles, survey reports, white papers, and e-books for enterprise and technology audiences. He has also moderated panel discussions and executive roundtables featuring CISOs, security researchers, and industry leaders. Jai previously served as senior editor at Computerworld, where he covered information security and data-privacy issues. His work has also appeared in CSO Online, InformationWeek, The Christian Science Monitor Passcode, The Economic Times, and other publications. His work has earned multiple industry honors, including a Joint ASBPE Excellence Award for Best Coverage of Government IT, and a Joint Jesse H. Neal Award for wireless LAN security coverage. Jai holds a Master’s degree in statistics from Bangalore University, and studied broadcasting and electronic communication at Marquette University in Milwaukee. Want more Dark Reading stories in your Google search results? ADD US NOW More Insights Industry Reports The State of Cloud Security: The Latest Challenges How Organizations Are Managing Incident Response How Enterprises Are Developing Secure Applications Inside RSAC 2026: security leaders reveal the risks redefining your defense strategy Essential News & Insights from Black Hat USA 2025 Access More Research Webinars The Dos and Don'ts of a Cybersecurity Awareness Month People Actually Remember Building a Secure AI Strategy for the Enterprise Is your AppSec program Mythos Ready? Experts Explain How to Develop a Framework for Cyber-Fraud Fusion Prevention at Machine Speed: Hunting Beyond Known Detections More Webinars You May Also Like CYBERATTACKS & DATA BREACHES Russian Hackers Weaponize Microsoft Office Bug in Just 3 Days by Jai Vijayan FEB 03, 2026 CYBERATTACKS & DATA BREACHES CISA Warns of 'Ongoing' Brickstorm Backdoor Attacks by Rob Wright DEC 04, 2025 CYBERATTACKS & DATA BREACHES Deja Vu: Salesforce Customers Hacked Again, Via Gainsight by Nate Nelson NOV 21, 2025 CYBERATTACKS & DATA BREACHES Jaguar Land Rover Shows Cyberattacks Mean (Bad) Business by Robert Lemos OCT 03, 2025 Editor's Choice CYBER RISK Sherlock Holmes Was the 'OG' Social Engineer byArielle Waldman AUG 10, 2026 3 MIN READ CYBERATTACKS & DATA BREACHES Déjà Vu? Meta's AI Escapes Testing Lab in Hacking Joyride byNate Nelson AUG 6, 2026 4 MIN READ THREAT INTELLIGENCE AI Sends Global Crime Syndicates Into Fraud Nirvana byTara Seals AUG 5, 2026 9 MIN READ Want more Dark Reading stories in your Google search results? Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox. SUBSCRIBE
    💬 Team Notes
    Article Info
    Source
    Dark Reading
    Category
    ◇ Industry News & Leadership
    Published
    Aug 13, 2026
    Archived
    Aug 13, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗