“City-Forum” Data-Theft Campaign Targets Salesforce and ServiceNow Portals Worldwide

A growing cyberattack campaign dubbed “City-Forum” is targeting organizations worldwide by exploiting data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals, according to SaaS security firm Reco.

The campaign involves the use of custom-built tools designed to extract sensitive information from publicly accessible portal environments. Researchers say the activity remains ongoing, with attacks continuing to increase.

Single Server Linked to Multiple Targets

According to Reco, the campaign has been traced to a single server that has been used to target multiple organizations across different industries.

The victims reportedly include telecommunications companies, banks and financial institutions, enterprise software providers, cybersecurity and data-privacy firms, and public-sector portals.

The broad range of targets highlights the potential scale of the campaign and the risks associated with improperly configured customer-facing SaaS platforms.

Anonymous Access Becomes a Security Risk

At the centre of the campaign is data that organizations have made accessible through portals designed to allow interaction with customers or the public.

While anonymous access can be a legitimate feature of cloud platforms, improperly configured permissions can unintentionally expose information that should remain restricted.

Attackers behind City-Forum appear to be taking advantage of these exposures, using automated and customized tooling to identify and extract available data.

Attacks Are Still Underway

Reco warns that the campaign is not a historical incident. Its researchers say the activity is continuing and has been increasing, raising concerns that additional organizations could become targets.

The campaign also demonstrates how attackers are increasingly focusing on SaaS applications and cloud-based business platforms, rather than relying solely on traditional network intrusion techniques.

A Wake-Up Call for SaaS Security

The City-Forum campaign underscores the importance of regularly auditing anonymous-access settings, portal permissions, exposed records and authentication controls across Salesforce and ServiceNow environments.

Organizations using customer-facing cloud portals need to ensure that information intended for authenticated users cannot be retrieved through anonymous access.

As the campaign continues, security teams are being urged to closely monitor their SaaS environments and investigate unusual data-access patterns before exposed information can be harvested on a larger scale.

Irfan Latif

Irfan Latif