Researchers say a stealthy campaign called City-Forum is quietly pulling exposed data from Salesforce and ServiceNow sites that allow too much guest access. Reco says the attackers use a custom Go-based toolset against Salesforce Experience Cloud Aura and Lightning Web Runtime (LWR), including what it calls the first observed in-the-wild abuse of Salesforce's UI API guest surface, and also hit a little-documented ServiceNow Service Portal search endpoint. Targeting has included telecoms, banks, software vendors, and public-sector portals.
Why it matters: Organizations using Salesforce Experience Cloud or ServiceNow portals may be leaking data to anyone on the internet if guest permissions are too broad. This is an exposure and active-threat story, not just theory: admins should urgently review guest-user permissions, self-registration settings, exposed portal endpoints, and logs for enumeration and bulk data access.
info@thehackernews.com (The Hacker News)
2026.08.18
96% relevant
This appears to be the same underlying campaign and adds attribution and timeline detail: one attacker has allegedly scraped both Salesforce and ServiceNow portals since 2025, reinforcing that the activity spans both platforms and is not isolated to one vendor.
Lawrence Abrams
2026.08.12
99% relevant
This article is a direct report on the same City-Forum campaign, adding specifics on the infrastructure, user agent, targeted Salesforce Aura and LWR endpoints, ServiceNow portal search abuse, and the campaign’s focus on anonymously accessible guest data.
Kevin Townsend
2026.08.12
100% relevant
This article appears to establish a distinct campaign, City-Forum, separate from previously tracked ShinyHunters Salesforce activity because it adds ServiceNow targeting, Salesforce LWR and UI API guest-surface exploitation, and a custom multi-platform toolset.
← Back to all stories