Mystery attacker spent a year raiding Salesforce and ServiceNow portals
Custom tools harvested whatever over-permissioned guest accounts would surrender
An unidentified attacker, dubbed City-Forum, has conducted a year-long operation to mine data from Salesforce and ServiceNow portals globally. This operation, named after a connected domain, has been ongoing since March 2025, although the exact start date is unknown. The attacker's targets include telecoms companies, banks, financial services firms, enterprise software vendors, cybersecurity companies, and public sector bodies.
During this period, the attacker has been consistently active and increasing the intensity of its actions. Nitay Bachrach, a senior security researcher at Reco, noted that the attacker is unique in its approach to Salesforce's Lightning Web Runtime (LWR) sites via the UI API's GraphQL layer, a technique not previously documented.
At ServiceNow, the attacker queries a native Service Portal search endpoint, which has received little public attention. The tooling used by the attacker is based on undisclosed research and techniques, indicating a high level of sophistication. The attacker created custom tooling, studying common data leak vectors to map out various data leak pathways.
One of the most active Salesforce targets was hit with over 560,000 events from the attacker's IP during the campaign. City-Forum has maintained the same IP address and domain for at least 17 months, using the same infrastructure across multiple organizations worldwide. While ServiceNow acknowledged the security company's blog post, it emphasized that no breach has been alleged, and they are investigating the matter.
Salesforce has not yet commented on the issue. Reco cautions that this attack is not a platform vulnerability but highlights the risk of over-permissioned guest accounts, allowing anyone on the internet to access data they should not be able to see.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.