Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

A Long-Running Data Theft Campaign Targets Salesforce and ServiceNow Users Worldwide

A sophisticated threat actor has been using custom-built tools to steal sensitive data from organizations that use Salesforce and ServiceNow platforms. The campaign, dubbed “City-Forum” by researchers at AI cybersecurity firm Reco, has been active since at least March 2025 and has targeted multiple sectors worldwide.

The attackers appear to have spent considerable time researching both platforms, identifying vulnerabilities in how guest users are granted access to sensitive data. They’ve built custom tools that allow them to interact directly with the underlying data-access layers of these platforms, bypassing standard security controls. This level of sophistication sets City-Forum apart from other recent campaigns targeting Salesforce and ServiceNow environments.

One of the most notable aspects of this campaign is its ability to target newer Salesforce sites that use the Lightning Web Runtime (LWR) framework. By figuring out how to interact with LWR’s data-access layer, the attackers can retrieve records from exposed surfaces accessible to guest users. This is a more advanced approach than seen in previous campaigns, where attackers relied on publicly available tools to scan for vulnerable areas.

ServiceNow has also been targeted using the same custom toolset. The attackers have identified a relatively obscure search endpoint that offers little online documentation or known open-source tools. By mapping these previously unexplored data-leak paths across both platforms, the threat actor demonstrates an advanced level of understanding and expertise.

The potential exposure for affected organizations is significant. On Salesforce, this could include sensitive customer information such as Social Security numbers, medical data, financial data, credit card numbers, and passport information. Support tickets and their content, calendar and email data, including internal emails and meetings, are also at risk. ServiceNow’s highly configurable nature means that the potential exposures can vary depending on each organization’s setup, but could include knowledge base articles containing sensitive data.

According to researchers, the targets of this campaign have spanned multiple sectors worldwide, including telecommunications, financial services, enterprise software, security and data-privacy companies, and public-sector portals. The Salesforce campaign appears much larger than the ServiceNow one, with more targets being compromised.

The City-Forum campaign serves as a stark reminder that even seemingly secure systems can be vulnerable to determined attackers. It highlights the importance of ongoing security research and awareness, as well as the need for organizations to regularly review their access controls and data configurations. By taking proactive steps to identify and address potential vulnerabilities, businesses can reduce their exposure to these types of attacks.

As a practical takeaway from this campaign, it’s essential for organizations using Salesforce or ServiceNow to conduct regular audits of their guest user access and ensure that sensitive data is not inadvertently exposed. This may involve reviewing access controls, updating configurations, and implementing additional security measures to mitigate potential risks. By staying vigilant and proactive in the face of evolving threats, businesses can minimize their exposure to sophisticated attacks like City-Forum.


Source: Dark Reading — 2026-08-12