City-Forum Campaign Exploits Unintentional Access to Data in Salesforce and ServiceNow
An ongoing data theft campaign dubbed 'City-Forum' is targeting organisations across various sectors by exploiting information exposed to unauthenticated users through Salesforce Experience Cloud and ServiceNow customer portals.
The attacks do not exploit a vulnerability in Salesforce or ServiceNow, but instead target information that organisations have unintentionally made accessible to guest users through permissive sharing rules, permissions, or portal configurations.
SaaS security firm Reco said the activity has been traced to a single server and continues to increase. The same infrastructure is associated with the city-forum.com domain, which has resolved to the server since at least March 2025.
The attacks have targeted both Salesforce's older Aura framework and newer Lightning Web Runtime framework. In the former, attackers probe publicly accessible objects such as Accounts, Contacts, and Cases before attempting to retrieve exposed records. In the latter, the attacker uses Salesforce's UI API and GraphQL requests to retrieve information exposed to guest accounts.
Reco advised administrators to review guest-user sharing rules, object and field permissions, file access, member visibility, and self-registration settings to prevent similar attacks in the future.