INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Salesforce and ServiceNow Hit by Long-running Data Theft Campaign
| 2026-08-12 21:08 DATA BREACH
Executive Summary
AI-generated
An unknown threat actor has been using a custom toolset to probe Salesforce and ServiceNow instances with overly permissive guest access, stealing data for over a year since at least March 2025. The targets spanned multiple sectors worldwide, including telecommunications, financial services, enterprise software, security and data-privacy companies, and public-sector portals. Researchers have dubbed the campaign "City-Forum" after the domain name linked to the attacker's IP address. This actor appears to have developed new techniques for reaching less-documented interfaces like Salesforce's Lightning Web Runtime (LWR) and ServiceNow's search endpoint, mapping multiple data-leak paths across both platforms. The attacks suggest an advanced actor who has created their own toolset based on research and unwell-documented online techniques, potentially exposing account data, contact information, leads, users, content document files in Salesforce, and knowledge bases and catalogs in ServiceNow.
Technical Mitigations AI-generated
• Patch Salesforce instances using Lightning Web Runtime (LWR) to prevent attackers from interacting directly with the runtime's underlying data-access layer.
• Block or hunt for ServiceNow Service Portal search endpoint vulnerabilities, as they have almost no online documentation or well-known open source tools.
• Monitor guest access on both Salesforce and ServiceNow platforms for overly permissive settings that could expose sensitive data.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Incident Timeline
Intelligence Sources
Dark Reading
2026-08-12