Skip to Content
Join the Network with Us — Join Membership


Data Theft Campaign Exploits Guest Access in Salesforce, ServiceNow Portals

August 13, 2026

An ongoing data theft campaign, dubbed "City-Forum," is targeting information exposed to unauthenticated users through Salesforce Experience Cloud and ServiceNow customer portals. The campaign is affecting organisations across multiple sectors, including telecommunications, banking, financial services, enterprise software, security, data privacy, and the public sector.

A Single Server Behind a Growing Campaign

SaaS security firm Reco says the activity has been traced back to a single server, and the campaign continues to grow. Importantly, these attacks aren't exploiting any actual vulnerability in Salesforce or ServiceNow's software. Instead, they're targeting information that organisations have unintentionally made accessible to guest users, through overly permissive sharing rules, permissions, or portal configurations — essentially exploiting misconfiguration rather than a technical flaw.

Tracing the Infrastructure

The activity has been linked to IP address 158.220.87.79, hosted by German VPS provider Contabo. This same infrastructure is associated with the city-forum.com domain, which has resolved to this server since at least March 2025.

According to Reco, similar technical fingerprints have shown up in attacks against both Salesforce and ServiceNow environments across multiple organisations worldwide. So far, the observed activity has involved guest users rather than authenticated accounts. Both platforms use guest accounts to provide access to unauthenticated visitors — but if permissions accidentally expose internal records to those accounts, information can potentially be pulled out through publicly reachable API interfaces.

How Salesforce Environments Are Being Targeted

Much of the Salesforce-focused activity has centred on the older Aura framework, where attackers probe publicly accessible objects like Accounts, Contacts, and Cases before attempting to retrieve exposed records. One particularly heavily targeted environment recorded more than 560,000 events from the attacker's IP address alone, with most of that activity linked to guest Aura enumeration — essentially, systematically probing to see what data could be pulled.

The campaign has also gone after Salesforce sites built on the newer Lightning Web Runtime framework. In these environments, the attacker uses Salesforce's UI API and GraphQL requests to retrieve information exposed to guest accounts. Interestingly, the attacker has also been checking Experience Cloud self-registration functions — potentially trying to identify whether a guest user could create an authenticated external account with broader access, which would be a significant escalation if successful.

Reco noted that similar Salesforce guest-user abuse has previously appeared in ShinyHunters data theft campaigns, but stressed there's currently no evidence directly connecting City-Forum to that group.

ServiceNow Portals Facing Automated Probing Too

ServiceNow Service Portals are being targeted through their native search functionality, which can accept anonymous requests and return information whenever search configurations happen to permit guest access. Attackers are varying their search terms to enumerate exposed data — in one examined environment, request volumes rose from just dozens per day to hundreds.

Reco said defenders may be able to detect automated searches and track the volume of information being returned, though ServiceNow's transaction logs don't record the POST body itself, which makes it genuinely difficult to pin down the precise search terms being used in these attacks.

What Organisations Should Do

Administrators have been advised to review guest-user sharing rules, object and field permissions, file access, member visibility, and self-registration settings across their Salesforce and ServiceNow environments. For Lightning Web Runtime sites specifically, disabling unnecessary guest access to public APIs can also help restrict the endpoints being used for data enumeration and theft — a practical step that could close off much of the exposure this campaign has been exploiting.

FAQs

Q1. What is the "City-Forum" data theft campaign targeting?

The campaign targets information unintentionally exposed to unauthenticated guest users through misconfigured Salesforce Experience Cloud and ServiceNow customer portals.

Q2. Does this campaign exploit a vulnerability in Salesforce or ServiceNow?

No, the attacks don't exploit any software vulnerability. Instead, they target overly permissive sharing rules, permissions, or portal configurations that expose data to guest accounts.

Q3. What steps can organisations take to protect against this campaign?

Administrators are advised to review guest-user sharing rules, object and field permissions, file access, and self-registration settings, and disable unnecessary guest access to public APIs on Lightning Web Runtime sites.

in News
Share this post
Archive