VYPR
breachPublished Aug 12, 2026· 2 sources

Stealthy 'City-Forum' Attacks Target Salesforce and ServiceNow with Custom Toolset

A sophisticated threat actor known as City-Forum is exploiting unauthenticated guest access to stealthily enumerate and exfiltrate data from Salesforce and ServiceNow instances.

A newly identified threat actor, operating under the moniker 'City-Forum,' has been observed conducting stealthy and targeted attacks against organizations utilizing Salesforce and ServiceNow platforms. The campaign focuses on exploiting unauthenticated guest access features inherent in these widely used Software-as-a-Service (SaaS) applications. By leveraging these overlooked entry points, attackers can enumerate exposed data and exfiltrate sensitive information without triggering standard authentication alerts.

The modus operandi of City-Forum involves a custom-built toolset, indicating a significant investment in developing specialized capabilities for this campaign. This bespoke tooling suggests a deliberate and sophisticated approach, moving beyond generic exploit kits. The attackers' ability to identify and weaponize unauthenticated guest access points highlights a deep understanding of the target platforms' architectures and potential security weaknesses. This method allows for a low-noise reconnaissance and data theft operation, making it difficult for security teams to detect.

Researchers first observed this novel campaign as it quietly enumerated and exfiltrated exposed data from both Salesforce and ServiceNow instances. The primary objective appears to be data theft, with attackers focusing on information that is accessible through guest or public-facing portals. This could include customer data, employee information, or other sensitive business intelligence that has been inadvertently exposed or misconfigured to be accessible by unauthenticated users.

The implications of these attacks are significant for organizations relying on Salesforce and ServiceNow for customer relationship management and IT service management, respectively. Compromised data could lead to regulatory fines, reputational damage, and further downstream attacks. The stealthy nature of the campaign means that many organizations may already be compromised without their knowledge, as the exfiltration methods are designed to blend in with normal network traffic.

While specific details about the custom toolset remain under analysis, the use of such tailored resources points towards a persistent threat actor with a clear objective. The campaign's focus on widely adopted enterprise platforms suggests a broad potential impact across various industries. Security professionals are advised to review their configurations for unauthenticated access, particularly for guest user roles and public-facing portals within their Salesforce and ServiceNow environments.

Further investigation into the specific vulnerabilities exploited and the full scope of the custom toolset is ongoing. However, the emergence of City-Forum and its sophisticated attack methodology serves as a stark reminder of the evolving threat landscape targeting cloud-based services. Organizations must remain vigilant in securing their SaaS deployments, implementing robust access controls, and regularly auditing their security configurations to prevent such stealthy data exfiltration campaigns.

This new reporting from Help Net Security provides additional technical depth on the City-Forum campaign, detailing how the threat actor specifically targeted the data layer behind Salesforce's newer site framework and an undocumented ServiceNow portal search endpoint. It highlights that the attacker developed custom tools rather than using off-the-shelf exploits, and has maintained a single server infrastructure for at least 17 months, a longer duration than typically seen in similar campaigns.

Synthesized by Vypr AI