Sophisticated ‘City-Forum’ Campaign Targets Salesforce and ServiceNow with Custom Toolset
A highly skilled threat actor has been quietly targeting major companies using a custom-made toolset that exploits vulnerabilities in both Salesforce and ServiceNow. Dubbed “City-Forum,” this campaign has been observed hitting telecoms, banks, financial services firms, enterprise software vendors, and public sector portals.
The attackers are using a single machine to launch the attacks, which reduces their footprint and makes it harder for security systems to detect them. The toolset appears to be custom-made, as opposed to off-the-shelf products like AuraInspector used in previous campaigns. This level of innovation is concerning, as it indicates that the threat actor has invested significant time and resources into developing this sophisticated attack.
One of the primary targets of City-Forum is the Guest User account on both Salesforce and ServiceNow platforms. These accounts are designed to allow unauthenticated users to access certain features, but they also pose a significant security risk if not properly configured. The attackers can use these guest user accounts to read sensitive data and even convert them into authenticated users in some cases.
The campaign has been observed targeting both Salesforce Aura and LWR implementations, with the latter being specifically targeted using GraphQL queries. ServiceNow is also being targeted through its effectively undocumented search endpoint. While there is no evidence of a breach of either platform, the attackers are able to exfiltrate sensitive data that has been inadvertently exposed by their victims.
What makes City-Forum particularly concerning is its stealthy nature. The attacks are carried out using legitimate protocols and are designed to be high-volume but low-noise. This makes it difficult for security systems to detect them, even if they are aware of the attack. Furthermore, the use of a single constant destination address suggests that the attackers are trying to keep a low profile.
It’s worth noting that Reco, the research firm behind this discovery, is not ruling out the possibility that ShinyHunters may also be behind City-Forum. The level of sophistication and innovation in this campaign is unprecedented, and it highlights the growing threat landscape that companies face today.
In light of these findings, companies using Salesforce or ServiceNow should take immediate action to review their guest user account configurations and ensure that they are not inadvertently exposing sensitive data. It’s also essential for security teams to be aware of the potential risks associated with guest user accounts and to implement robust monitoring and detection systems to identify any suspicious activity.
Ultimately, City-Forum serves as a reminder that even seemingly secure platforms can be vulnerable to sophisticated attacks if not properly configured or monitored. As the threat landscape continues to evolve, companies must stay vigilant and adapt their security strategies to keep pace with the latest threats.
Source: SecurityWeek — 2026-08-12