Stealthy âCity-Forumâ Attacks Target Salesforce and ServiceNow With Custom Toolset
Reco is tracking a sophisticated and innovative campaign targeting both Salesforce and ServiceNow via what appears to be a custom made multi-platform toolset.
Researchers believe the primary targets include telecoms, banks and financial-services firms, enterprise-software vendors (including security and data-privacy companies), and public-sector portals.
The campaign has been named âCity-Forumâ. It is directed at both Salesforce Aura and the newer LWR implementations, where it is the first observed inâtheâwild exploitation of Salesforceâs UIâAPI guest surface. Furthermore, attacks on Aura (necessarily included in a Salesforce campaign since Aura users still outnumber LWR users) are integrated with the LWR attacks in a single toolset.
âOne Go binary hit Salesforce over both Aura and LWR and hit ServiceNow, from the same box,â comment the researchers in a blog report. This is consistent with a custom toolset rather than anything off the shelf like AuraInspector.
The primary access key for both platforms is the Guest User. Every Salesforce Experience Cloud has its own Guest User in which an unauthenticated request works. ServiceNow is similar. âYou cannot delete those guest users, and requiring login doesnât remove them â the profile, its permissions, its sharing rules, and any code running in its context all still exist. If the guest can read a record, so can anyone on the internet.â
To better understand the degree of innovation in this campaign, it is useful to compare the City-Forum campaign with other attacks targeting Aura â especially the ShinyHuntersâ Salesforce Aura Campaign disclosed in March 2026. As well as targeting LWR in Salesforce, â[City-Forum] hammers a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open source tools.â
ShinyHunters targeted just Aura in Salesforce (no known targeting of ServiceNow) and used a modified version of the existing AuraInspector. City-Forum uses a new custom multi-platform toolset.
Reco is at pains to explain that it doesnât rule out ShinyHunters also being behind City-Forum, and goes on to add âWe donât know who this is, and weâre not ruling anyone in or out.â
The City-Forum campaign uses a single machine. âThe same IP has carried the same domain since March 2025 and is still scanning today â at least seventeen months on one address, with no rotation at any point.â That IP (158.220.87.79) resolves to city-forum.com.
Reco draws no inference from this, but the main advantage of a single machine is that it reduces the attackerâs footprint to anomaly detection systems. It may be easier to block if known, but harder to detect if stealthy.
The campaign targets unauthenticated guest user access in both Salesforce and ServiceNow. However, conversion to an authenticated user in Salesforce would be possible if self-registration is enabled. There is no similar mechanism for ServiceNow.
Being an authenticated guest user is not necessary, but could provide access to more sensitive data. Since many organizations misconfigure guest permissions, this is a continuing possibility. However, âSo far, we have only seen guest user activities â never an authenticated user, but we cannot rule it out,â comment the researchers.â
Aura gives up the majority of the Salesforce data collected and exfiltrated. âThe busiest target logged over 560,000 events⌠across the campaign window, essentially all of it guest Aura enumeration,â say the researchers. Data is also pulled from the Salesforce LWR sites using GraphQL.
The ServiceNow attack targets the effectively undocumented search endpoint. It uses this to detect substantial content. âThe Output length column is worth a glance while youâre here: rows returning noticeably more than the small empty-result baseline are searches that came back with content.â The attacker can pull from the most likely results.
The exfiltration is not noisy â it is high volume but protocol-legitimate. This makes detection difficult, perhaps confirming the stealth intent behind using a single constant destination address.
As with the ShinyHunters attack, there is no suggestion of a breach of the Salesforce or ServiceNow platforms. âEvery byte the attacker retrieved was something a site owner had exposed to anonymous users.â
Being targeted by City-Forum is not a noisy easy-to-see attack. But most things can be found if you know where to look. The Reco research blog includes detailed IOCs and remediation instructions. At the very least, as soon as possible make sure that self-registration is not enabled. This will hinder any attempt for an unauthenticated guest to upgrade to an authenticated guest.
Related: BeyondTrust, LastPass Impacted by Klue-Salesforce Incident
Related: Salesforce Instances Hacked via Gainsight Integrations
Related: Extortion Group Leaks Millions of Records From Salesforce Hacks
Related: Hackers Extorting Salesforce After Stealing Data From Dozens of Customers
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content â general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached â you'll always get the same 5 for this article.