A newly documented data theft campaign called City-Forum is actively targeting the public-facing portals of Salesforce and ServiceNow. The operation exploits permissive configurations and guest access privileges to silently exfiltrate sensitive corporate data. Researchers have recorded over 560,000 attacks directed at organizations across multiple sectors worldwide.
What We Know About the City-Forum Campaign
City-Forum has been active since at least March 2025. The threat actor behind the campaign remains unidentified, and researchers are keeping all attribution hypotheses on the table.
A Custom, Multi-Platform Toolset
What sets City-Forum apart is its technical arsenal. The attackers deploy a custom-built toolset designed to simultaneously target Salesforce Experience Cloud and ServiceNow Service Portal. All observed activity originates from a single infrastructure source — researchers have traced an IP address back to a rented hosting environment based in Germany.
Critically, this campaign does not exploit known software vulnerabilities or rely on stolen credentials. Instead, attackers simply abuse overly permissive configurations. Public-facing portals, case submission forms, and search functions exposed to anonymous users become the primary attack vector.
Opportunistic and Scalable Targeting
City-Forum stands out for its distinctly opportunistic nature. There is no specific industry in the crosshairs — the attackers are hunting for any organization with misconfigured guest access. This approach makes the threat both scalable and difficult to anticipate.
The Broader Picture: SaaS Cloud Portal Abuse
City-Forum is not an isolated phenomenon. It is part of a broader and growing trend of corporate SaaS and cloud portal abuse that has intensified significantly over the past 12 months.
Three Recurring Patterns in Public Portal Abuse
Researchers have identified at least three recurring patterns across this category of campaigns.
The first involves harvesting data from customer support or case management portals exposed to guest users. The typical outcome is silent exfiltration, often without triggering any obvious alerts.
The second targets search endpoints or SaaS APIs designed for limited public use. Attackers exploit these to collect data in an unauthorized manner, sidestepping conventional security triggers.
The third, and broadest, involves abusing identity and collaboration platforms through weak access controls — a pattern that frequently leads to massive data exposures and reactive hardening efforts after the fact.
Salesforce and ServiceNow are particularly attractive targets in this landscape. Organizations routinely expose knowledge bases, forms, and search functionalities to unauthenticated users. When permissions are not properly scoped, the risk of data exposure becomes very real.
How to Defend Against City-Forum-Style Attacks
For CISOs and security managers, the good news is that effective controls do exist. However, they require active configuration governance — not just traditional security tooling.
Review Guest Permissions and Public Configurations
The first step is a comprehensive audit of guest and anonymous access across Salesforce and ServiceNow environments. Organizations must determine which objects, fields, and search endpoints are publicly exposed. Where guest access is not operationally necessary, it should be disabled entirely.
Regular configuration audits are equally essential. Portal settings drift over time, and a structured, periodic review significantly narrows the window of exposure.
Monitoring and Anomaly Detection
Organizations should also enable detailed logging and alerting on guest user activity. Key signals to watch for include unusual query volumes, repeated search and export behaviors, and anomalous access patterns on public-facing endpoints.
Rate-limiting and bot-detection controls can further reduce the risk of automated scraping — intercepting malicious automation before it can extract data at scale.
Make Secure Configuration Management a Priority
This is a point worth emphasizing for security leaders: this class of attack is not stopped by antivirus software or signature-based detection systems. The primary investment must go toward secure configuration management, continuous monitoring, and periodic penetration testing of externally exposed portals.
Conclusions
The City-Forum campaign is a clear signal that the corporate attack surface has fundamentally shifted. Patches and firewalls alone are no longer sufficient. Permissive cloud portal configurations have become a primary data exfiltration vector. Organizations running Salesforce or ServiceNow need to act now — with targeted audits and rigorous governance of public-facing access.
Sources:
Source: Original article
Campaigns like City-Forum underscore how timely, shared threat intelligence is decisive in getting ahead of attacks rooted in cloud misconfiguration. IsacChain enables organizations to securely and anonymously share indicators of compromise and attack patterns among ISAC members, accelerating the detection of similar threats before they strike. The platform’s integrated automated NIS2 compliance ensures that every report meets current regulatory requirements, while blockchain-based verification guarantees the integrity and traceability of every piece of shared data. Discover how IsacChain can help your organization at www.isacchain.com