Threats

Salesforce and ServiceNow Targeted by City-Forum Data Theft Attacks

August 13, 2026 12:06 · 12 min read
Salesforce and ServiceNow Targeted by City-Forum Data Theft Attacks

City-Forum Data Theft Attacks Target Salesforce and ServiceNow Portals

An ongoing data theft campaign, dubbed City-Forum by SaaS security firm Reco, has been targeting Salesforce Experience Cloud and ServiceNow customer portals, stealing data exposed to anonymous users through custom tools.

The attacks, which have been traced to a single server with the IP address 158.220.87.79, have been ongoing, with activity continuing to increase, according to Reco. The server, hosted by German VPS provider Contabo, has been associated with the city-forum.com domain since at least March 2025.

Attack Methodology

The attackers use the default Go-http-client/1.1 user agent when downloading data and target guest user activities, never authenticated users, although Reco cannot rule out the possibility of authenticated user exploitation. The attacks do not exploit a vulnerability in Salesforce or ServiceNow but instead steal data that organizations have mistakenly exposed to unauthenticated guest users through overly permissive sharing rules, permissions, or portal configurations.

On Salesforce, the attackers target the older Aura framework, sending requests to the /aura or /s/sfsites/aura endpoint to determine which objects, such as Accounts, Contacts, Cases, are publicly accessible. They then use the HostConfigController.getConfigData and SelectableListDataProviderController.getItems APIs to retrieve records from accessible objects.

The busiest target recorded more than 560,000 events from the attacker's IP address, with nearly all of them related to guest Aura enumeration. The attackers also target Salesforce sites built using the newer Lightning Web Runtime (LWR) framework, using Salesforce's UI API to steal data exposed to guest accounts through GraphQL requests sent to /webruntime/api/services/data/{version}/graphql.

ServiceNow Attacks

The same attackers target ServiceNow Service Portals through the native POST /api/now/sp/search?sysparm_cancelable=true endpoint, which accepts anonymous requests and can return data when search sources are configured to permit guest access. The attackers can vary search terms to enumerate exposed information, with one investigated environment seeing requests grow from tens to hundreds per day.

Because ServiceNow transaction logs do not record the POST body, defenders can see that automated searches occurred and how much data was returned, but cannot determine the exact search terms used by the attacker.

Prevention and Recommendations

Salesforce administrators are advised to review guest-user sharing rules, object and field permissions, file access, member visibility, and self-registration settings. For LWR sites, Reco recommends disabling the Experience Builder option that allows guest users to access public APIs when it is not required, which will block access to various API endpoints used for data enumeration and theft.

ServiceNow administrators should review which search sources are exposed through Service Portals and ensure that sensitive data search sources use strict authentication and access controls. According to The Blue Report 2026, once attackers have valid credentials, only 37% of their actions are blocked, highlighting the importance of robust security measures.

The City-Forum data theft attacks demonstrate the need for organizations to carefully review and configure their Salesforce and ServiceNow portals to prevent data exposure to anonymous users. By taking proactive measures to secure their portals, organizations can reduce the risk of data theft and protect their sensitive information.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free