Urgent.News

What's breaking now, across thousands of outlets.

Tech

Mystery attacker spent a year raiding Salesforce and ServiceNow portals

Custom tools harvested whatever over-permissioned guest accounts would surrender

Mystery attacker spent a year raiding Salesforce and ServiceNow portals

An unknown attacker has spent over a year targeting Salesforce and ServiceNow portals globally, harvesting data that organizations inadvertently left exposed. The campaign, dubbed City-Forum, is ongoing and intensifying, according to researchers at Reco. The attacker's modus operandi involves targeting Lightning Web Runtime (LWR) sites on Salesforce through the UI API's GraphQL layer and querying a native Service Portal search endpoint on ServiceNow.

This unusual approach has not been documented in public research or incorporated into publicly available attack tools. The toolset used by the attacker is custom and not well-documented online, indicating an advanced threat actor. Reco identified Salesforce targets across various industries, including telecoms companies, banks, financial services firms, enterprise software vendors, cybersecurity companies, and public sector bodies.

One of the busiest Salesforce targets received over 560,000 events from the attacker's IP during the campaign, primarily involving attempts to enumerate data accessible to guest users. ServiceNow informed Reco that they are aware of the security company's claims and are investigating accordingly, but have not found any allegations of a compromise of their environment.

Salesforce has not yet responded to inquiries. City-Forum represents a distinct threat actor, different from ShinyHunters, which stole data from numerous high-profile companies and websites due to over-permissioned Experience Cloud guest accounts. Reco emphasizes that the attacker conducted all activities without authentication and collected information exposed through permissions, sharing rules, search sources, or other configuration choices.

This underscores the importance of proper configuration and access control to prevent unintentional data exposure.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

More from Thursday 13 August →