Skip to content
Tech News
← Back to articles

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

read original more articles
Why This Matters

The City-Forum data-theft campaign highlights the ongoing risks of exposing sensitive data through misconfigured customer portals like Salesforce and ServiceNow. This underscores the importance for organizations to tighten access controls and review sharing permissions to prevent unauthorized data breaches. As these attacks continue to grow, both industry and consumers must prioritize robust security practices to safeguard sensitive information in SaaS environments.

Key Takeaways

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals.

The data-theft campaign, dubbed City-Forum by SaaS security firm Reco, has been traced to a single server that has targeted multiple organizations worldwide. These organizations include telecommunications companies, banks and financial services firms, enterprise software vendors, security and data privacy companies, and public-sector portals.

Reco says the attacks are ongoing, with activity continuing to increase.

The City-Forum data theft attacks

Reco says all of the attacks originate from the IP address 158.220.87.79 , hosted by German VPS provider Contabo, and almost always use the default Go-http-client/1.1 user agent when downloading data.

This IP address is associated with the city-forum.com domain, which has resolved to the server since at least March 2025, indicating that the infrastructure has remained in place for more than a year.

The researchers say these combined IOCs have been seen across almost all attacks targeting Salesforce and ServiceNow environments in this campaign.

"The same fingerprint appears against both Salesforce and ServiceNow, across multiple organizations worldwide. It is still running, and the volume is climbing," explains Reco.

"So far, we have only seen guest user activities - never an authenticated user, but we cannot rule it out."

These attacks are not exploiting a vulnerability in Salesforce or ServiceNow.

... continue reading