Skip to content
feed: live
>_ 0dayNews
threat intel

City-Forum Campaign Targets Salesforce, ServiceNow

A data-theft operation running since March 2025 harvests records exposed through anonymous-access endpoints in Salesforce Experience Cloud and ServiceNow portals — no CVE required.

City-Forum Campaign Targets Salesforce, ServiceNow
Image: AI-generated — no human photographer / 0dayNews AI Cover (comfyui) · Generated on-site infrastructure — no external license
kilobaud Dave "Kilobaud" Ferris · Published · 2 min read

Most enterprise data-theft campaigns start with a stolen credential or an unpatched CVE. The “City-Forum” campaign takes a quieter path: it walks through doors organizations deliberately left open.

According to reporting by BleepingComputer and Dark Reading, the campaign has been operating since at least March 2025 — sixteen months of sustained activity — targeting data exposed through anonymous-access endpoints in Salesforce Experience Cloud and ServiceNow customer portals. No zero-day required. The custom tooling the attackers built exists specifically to harvest whatever organizations made visible to unauthenticated users.

What City-Forum Does

The attackers aren’t breaking into anything in the traditional sense. They built bespoke tooling to query Salesforce Experience Cloud portals and ServiceNow customer-facing instances for records accessible to guest or anonymous sessions — the same data visible to anyone who navigates to those portals without logging in. In deployments that haven’t restricted what anonymous sessions can touch, that exposure can be substantial: customer records, internal tickets, case histories, contact information.

The campaign has hit organizations across multiple sectors, Dark Reading reports. Salesforce Experience Cloud and ServiceNow are both deployed at significant enterprise scale; their customer-portal features are commonly configured during rollout and infrequently revisited in subsequent security reviews.

The Actual Problem

This isn’t a vendor vulnerability story. Salesforce and ServiceNow both provide controls for limiting what anonymous sessions can access — the question is whether administrators configure and maintain those controls over time, particularly as portal features expand and new content types are added. A portal that starts with sensible guest-access limits can drift into substantial exposure through incremental configuration changes that never individually trigger a formal review.

City-Forum isn’t exploiting a bug. It’s exploiting drift.

Sixteen months is a long time for a data-theft campaign to run undetected, which suggests the records being taken — content accessible to anonymous sessions — often doesn’t generate the alerts organizations watch for. There’s no authentication failure, no anomalous login, no credential-stuffing signature to catch. Just API queries to endpoints designed to accept them. The same mistake, in other words, that organizations have been making with misconfigured S3 buckets and public-facing database interfaces for the better part of a decade.

What to Do

Organizations running Salesforce Experience Cloud or ServiceNow customer portals should audit what records are currently accessible to guest or anonymous sessions, regardless of what the original configuration intended. Both platforms provide administrative tooling to enumerate and restrict anonymous-access scope.

If that review hasn’t happened in the past twelve months — or since the last significant portal expansion — it’s overdue. The campaign remains active as of current reporting.

For broader context on threat actors targeting enterprise tool stacks, see our coverage of the LiteLLM supply-chain attack that exposed cloud credentials at over 2,500 organizations.

Found this useful? Share it.