started · updated
City-Forum campaign targets Salesforce and ServiceNow portals
A sophisticated cyberattack campaign, dubbed ‘City-Forum’ by security provider Reco, has been targeting Salesforce and ServiceNow portals globally. The campaign, active since at least March 2025, utilizes a custom Go-based toolset to enumerate and collect data that organizations have inadvertently left accessible to unauthenticated guests.
In Salesforce attacks, the actor targets Experience Cloud via two methods: using the Aura endpoint to list and scrape objects like Accounts, Contacts, and Leads, and exploiting the GraphQL layer in newer Lightning Web Runtime (LWR) sites. The latter method allows the attacker to query up to 2,000 object definitions at once by iterating through API versions 56.0 to 66.0.
Simultaneously, the attacker uses the same infrastructure to scan ServiceNow Service Portals. By sending search terms to the guest portal API, the tool distinguishes between empty responses and available data to collect information.
Security experts emphasize that these attacks do not exploit platform vulnerabilities or software bugs. Instead, they exploit misconfigurations where sensitive data is permitted to be viewed by guest users. The remedy for organizations is to review and tighten permission settings and sharing rules rather than applying software updates.
Entities
Reco · Salesforce · ServiceNow