City-Forum Hackers Wreak Havoc on Salesforce and ServiceNow
A sophisticated threat actor has been running a large-scale cyber campaign targeting Salesforce Experience Cloud sites and ServiceNow Service Portals worldwide, dubbed 'City-Forum Campaign'.
The operation, which began at least March 2025, involves the attackers quietly siphoning data from various organizations, including telecommunications providers, banks, financial services firms, enterprise software vendors, and public-sector portals.
The City-Forum Hackers have engineered a more advanced approach than known cybercrime groups like ShinyHunters, leveraging both high-volume Aura enumeration and targeting Salesforce's newer Lightning Web Runtime (LWR) sites through UI-API, as well as an undocumented native search endpoint within ServiceNow Service Portals.
The combination of these tactics indicates that the threat actor has researched both cloud platforms to map out unexpected data-leak vectors. This highlights similar risks associated with service portal vulnerabilities.