Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

A Long-Running Data Theft Campaign Targets Salesforce and ServiceNow, Exposing Sensitive Information Worldwide

A sophisticated cyber threat actor has been conducting a long-running campaign of data theft against organizations using Salesforce and ServiceNow platforms, compromising sensitive information from multiple sectors around the world. The campaign, dubbed “City-Forum” by researchers at AI cybersecurity firm Reco, has been active since at least March 2025 and uses custom tooling to probe instances with overly permissive guest access.

The threat actor’s approach is notable for its level of research and customization, as they have developed their own tools to identify data that organizations may have inadvertently left accessible to guest users. This includes exploiting less-documented interfaces on newer Salesforce sites using the company’s Lightning Web Runtime (LWR), which allows them to interact directly with the runtime’s underlying data-access layer and retrieve records from exposed surfaces.

The campaign targets both platforms, but with different levels of success. The Salesforce campaign appears larger, with more targets being compromised, while the ServiceNow campaign is smaller in scale. However, the potential exposure on ServiceNow instances is significant, as knowledge bases and catalogs can contain sensitive information that may be accessible to attackers.

What’s striking about this campaign is the level of research and customization required by the threat actor. Unlike other attackers who rely on publicly available tools, City-Forum uses custom tooling developed through extensive research into both platforms. This approach suggests a high level of sophistication and resource investment, as well as a deep understanding of the services being targeted.

The potential impact of this campaign is significant, as it could compromise sensitive information from organizations across multiple sectors, including telecommunications, financial services, enterprise software, security and data-privacy companies, and public-sector portals. The types of data that are potentially exposed include customer information, support tickets, calendar and email data, knowledge base articles, and more.

While the campaign’s approach is notable for its level of sophistication, it’s essential to remember that this type of research can be replicated by attackers with significant resources and expertise. This highlights the importance of regularly reviewing and updating security configurations on both platforms, as well as implementing robust access controls and monitoring to detect potential data leaks.

As a practical takeaway, organizations using Salesforce or ServiceNow should review their guest user settings and ensure that they are not inadvertently exposing sensitive information. Regularly auditing and testing security configurations can help identify potential weak points in services like these, where attackers may exploit less-documented interfaces or other vulnerabilities. By staying vigilant and proactive in addressing these types of threats, organizations can reduce the risk of data breaches and protect their sensitive information from falling into the wrong hands.


Source: Dark Reading — 2026-08-12