"City-Forum" Campaign Targets Misconfigured Salesforce and ServiceNow Portals to Harvest Enterprise Data
A newly uncovered data-theft initiative, dubbed "City-Forum," is actively targeting enterprise organizations by exploiting security misconfigurations in popular cloud platforms. The ongoing campaign systematically scans for and extracts sensitive information exposed to the public through Salesforce Experience Cloud and ServiceNow customer portals.
Rather than relying on sophisticated zero-day exploits to breach secure networks, the threat actors behind City-Forum are capitalizing on administrative oversight. The campaign specifically hunts for instances where internal databases and customer portals have been inadvertently configured to allow anonymous or guest users access to sensitive corporate resources. Once these exposures are identified, the attackers leverage specialized, custom-built tools to rapidly exfiltrate the data.
Security analysts note that both Salesforce Experience Cloud and ServiceNow are heavily relied upon by global enterprises to manage customer relations, IT services, and internal workflows. Because these platforms hold vast repositories of proprietary business information and personally identifiable information (PII), they represent highly lucrative targets for cybercriminals. The automated nature of the City-Forum campaign allows attackers to scan thousands of portals simultaneously, identifying weak spots at scale.
The custom tools deployed in this campaign are engineered to navigate the specific architectures of Salesforce and ServiceNow. By mimicking legitimate queries, these tools can extract large volumes of data without triggering standard security alarms that typically flag brute-force intrusion attempts. This stealthy approach enables the operators of the City-Forum campaign to harvest massive datasets before organizations even realize their portals are leaking information.
This campaign highlights a persistent challenge in cloud security: the gap between platform security and user configuration. While both Salesforce and ServiceNow provide robust security controls, the complexity of managing permissions across massive enterprise deployments often leads to accidental exposures. Security experts urge administrators to immediately audit their external-facing portals, disable anonymous access where it is not strictly required, and implement strict access control lists to safeguard sensitive data from automated scraping tools.
Comments (0)
Be the first to comment.
Join the discussion