New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide

By Published On: August 13, 2026

A new, sophisticated threat actor is actively targeting Salesforce Experience Cloud sites and ServiceNow Service Portals on a global scale. This ongoing campaign, dubbed the “City-Forum Campaign,” has been observed silently exfiltrating sensitive data from a diverse range of organizations, including telecommunications providers, banks, financial services firms, enterprise software vendors, and various public-sector entities.

Understanding the City-Forum Campaign

The “City-Forum Campaign” derives its name from a domain associated with the attacker’s infrastructure. This nomenclature highlights the organized nature of the operation, which has been in progress for an extended period, meticulously siphoning data from high-value targets. The attackers’ focus on widely adopted enterprise platforms like Salesforce and ServiceNow underscores their strategic intent to compromise critical business operations and access sensitive corporate and customer information.

Targeted Platforms: Salesforce and ServiceNow

Salesforce Experience Cloud (formerly Community Cloud) is a platform designed to create connected digital experiences for customers, partners, and employees. ServiceNow Service Portals offer self-service capabilities and streamline IT, HR, and other enterprise services. Both platforms handle vast amounts of confidential data, making them lucrative targets for cybercriminals.

  • Salesforce Experience Cloud: Attackers are likely exploiting misconfigurations or vulnerabilities within these external-facing sites to gain unauthorized access to user data, customer records, and potentially internal system access if proper segregation is not maintained.
  • ServiceNow Service Portals: Similar to Salesforce, compromised ServiceNow portals could lead to the exposure of employee data, service requests, incident reports, and other sensitive operational information.

Tactics and Techniques of the Attackers

While specific technical details of the exploits used by the City-Forum attackers are still emerging, the long-running nature of the campaign suggests persistent and adaptive tactics. Initial assessments indicate a focus on data exfiltration, implying successful bypasses of existing security controls. Organizations utilizing these platforms should be particularly vigilant for signs of:

  • Unauthorized data access or modification.
  • Unusual login patterns or access attempts.
  • Suspicious activity within their Experience Cloud or Service Portal environments.
  • Indicators of compromise (IOCs) related to the attacker’s infrastructure, though specific IOCs for “City-Forum” are not yet publicly detailed in the provided source.

Impact and Potential Consequences

The successful compromise of Salesforce and ServiceNow instances can lead to severe consequences for affected organizations:

  • Data Breaches: Exposure of sensitive customer, financial, or operational data, leading to regulatory fines and reputational damage.
  • Financial Loss: Direct financial theft, fraud, or impact on stock prices due to public disclosure of a breach.
  • Operational Disruption: Tampering with critical business processes managed through these platforms.
  • Loss of Trust: Erosion of customer and partner confidence in the organization’s ability to protect their information.

Remediation Actions for Salesforce and ServiceNow Users

Proactive security measures are paramount to defend against campaigns like City-Forum. Organizations should immediately review and strengthen the security posture of their Salesforce and ServiceNow environments:

  • Regular Security Audits: Conduct frequent audits of your Salesforce Experience Cloud sites and ServiceNow Service Portals to identify and remediate misconfigurations, outdated access policies, and potential vulnerabilities.
  • Patch Management: Ensure all Salesforce and ServiceNow instances are running the latest security patches and updates. While the specific vulnerability exploited by City-Forum is not detailed, unpatched systems are always primary targets.
  • Access Control Review: Implement and enforce the principle of least privilege. Regularly review and revoke unnecessary access permissions for users, partners, and external integrations.
  • Multi-Factor Authentication (MFA): Mandate MFA for all user accounts, especially those with administrative privileges, across both platforms.
  • Monitoring and Logging: Enhance logging and monitoring capabilities for unusual activities, failed login attempts, and data access patterns within your Salesforce and ServiceNow environments. Integrate these logs with a SIEM for centralized analysis.
  • Penetration Testing: Engage independent security firms to perform penetration tests specifically targeting your Salesforce Experience Cloud sites and ServiceNow Service Portals to uncover exploitable weaknesses.
  • Data Encryption: Ensure that all sensitive data at rest and in transit is properly encrypted within both platforms.
  • Developer Best Practices: For custom implementations or integrations, enforce secure coding practices to prevent common web vulnerabilities like XSS, SQL injection, and insecure direct object references.

Recommended Tools for Enhanced Security

Leveraging specialized tools can significantly bolster your defense against sophisticated threats targeting enterprise platforms.

Tool Name Purpose Link
Salesforce Health Check Native tool for assessing security settings and configurations against recommended baselines. Salesforce Health Check
ServiceNow Security Operations Integrates security incident response, vulnerability response, and threat intelligence. ServiceNow Security Operations
OWASP ZAP (Zed Attack Proxy) Open-source web application security scanner for identifying vulnerabilities in custom portal developments. OWASP ZAP
Burp Suite Leading web vulnerability scanner and penetration testing tool for comprehensive security assessments. Burp Suite

Conclusion

The emergence of the “City-Forum Campaign” serves as a critical reminder of the persistent and evolving threat landscape. Organizations relying on Salesforce Experience Cloud and ServiceNow Service Portals must prioritize their security posture, implementing robust defenses and continuous monitoring. Proactive measures, including vigilant patch management, strong access controls, and regular security assessments, are essential to protect sensitive data and maintain the integrity of these vital business platforms.

Share this article

Leave A Comment