V-Help
← All news
Security

City-Forum Attacks: Hackers Steal Data from Salesforce and ServiceNow

City-Forum Attacks: Hackers Steal Data from Salesforce and ServiceNow

Photo: BleepingComputer

Quick answer

The City-Forum campaign exploits misconfigured Salesforce and ServiceNow portals to steal data exposed to anonymous users via improper access settings.

Cybercriminals are conducting a large-scale data theft campaign targeting corporate portals Salesforce Experience Cloud and ServiceNow. Dubbed City-Forum, the attacks exploit misconfigured access settings that allow anonymous users to retrieve confidential information via APIs. Security experts at Reco, who discovered the threat, report that attacker activity continues to escalate while their infrastructure has remained unchanged since March 2025.

All attacks originate from a single IP address (158.220.87.79), registered to German hosting provider Contabo. The threat actors use a standard user agent (Go-http-client/1.1) and the domain city-forum.com, which has been linked to this server for over a year. The attacks target data erroneously exposed to guest users through excessive permissions or portal misconfigurations.

In Salesforce, attackers exploit both the legacy Aura framework and the modern Lightning Web Runtime (LWR). For Aura, they send requests to endpoints like /aura or /s/sfsites/aura to enumerate available objects such as accounts, contacts, or support cases. For LWR, they use GraphQL through the UI API to extract data via the /webruntime/api/services/data endpoint. In ServiceNow, attacks focus on the portal search API, which may return data when access permissions are misconfigured.

Experts emphasize that these attacks do not exploit platform vulnerabilities but instead abuse excessive access rights. To mitigate risks, organizations should review guest account settings, restrict API access, disable unnecessary self-registration features, and monitor logs for suspicious automated queries.

Common questions

What are City-Forum attacks?
A data theft campaign targeting Salesforce and ServiceNow portals, where hackers abuse misconfigured access settings to extract information available to anonymous users through APIs.
Which companies are at risk?
Telecom firms, banks, software developers, cybersecurity organizations, and government portals are most vulnerable. The attacks specifically target data erroneously exposed to unauthorized users.
How can organizations defend against City-Forum attacks?
Administrators should review guest account permissions, restrict API access, disable unnecessary self-registration features, and monitor logs for suspicious automated activity.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer