Stealthy City-Forum Campaign Targets Salesforce and ServiceNow with Custom Toolset
Researchers have discovered a sophisticated and custom-made toolset targeting both Salesforce and ServiceNow, dubbed 'City-Forum'. The campaign appears to be directed at telecoms, banks, financial-services firms, enterprise-software vendors, and public-sector portals. A single machine is used for the attack, with no rotation of IP addresses over seventeen months.
The attackers exploit unauthenticated guest user access in both Salesforce and ServiceNow. In Salesforce, this allows them to collect and exfiltrate data using GraphQL, while in ServiceNow, they target an effectively undocumented search endpoint. The output is high-volume but protocol-legitimate, making detection difficult.
The campaign has been compared to the ShinyHunters' Salesforce Aura Campaign disclosed in March 2026, with City-Forum using a new custom multi-platform toolset rather than modifying existing ones. Reco researchers note that they don't rule out ShinyHunters being behind City-Forum, but stress that this is currently unknown.