"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]
Source: BleepingComputer · August 13, 2026 at 7:45 AM · AI-assisted report

KUALA LUMPUR, 13 AUGUST 2026 —
Listen to this article
DomainFork Audio · read aloud
**Data-Theft Campaign Targets Salesforce, ServiceNow Portals via Misconfigured Guest Access**
An ongoing data-theft campaign, codenamed *City-Forum* by SaaS security firm Reco, is exploiting misconfigured guest-user access in Salesforce Experience Cloud and ServiceNow customer portals to steal exposed data. The attacks, traced to a single server (IP: 158.220.87.79) hosted by German VPS provider Contabo, have targeted telecommunications firms, banks, enterprise software vendors, security companies, and public-sector portals globally. Activity remains ongoing, with Reco reporting a rising volume of incidents since March 2025.
The campaign does not exploit vulnerabilities in Salesforce or ServiceNow but instead targets data inadvertently exposed to unauthenticated guest users due to overly permissive sharing rules or portal configurations. Both platforms use guest accounts to manage unauthenticated visitors, and if these accounts are granted access to records, the data becomes retrievable via API endpoints.
On Salesforce, attackers primarily target the older Aura framework, sending requests to `/aura` or `/s/sfsites/aura` endpoints to identify publicly accessible objects such as Accounts, Contacts, and Cases. Reco observed one environment recording over 560,000 events from the attacker’s IP, nearly all related to guest Aura enumeration.
The attacker also exploits Salesforce’s newer Lightning Web Runtime (LWR) framework, using the UI API to send GraphQL requests to `/webruntime/api/services/data/{version}/graphql` to steal data exposed to guest accounts. Reco notes this technique has not been observed in public attack tools, distinguishing it from previous campaigns like ShinyHunters, which used modified versions of AuraInspector.
Additionally, the attacker probes Salesforce Experience Cloud sites via `/SiteRegister` and `/CommunitiesSelfReg` endpoints to check for self-registration capabilities, which could grant authenticated external accounts broader access.
For ServiceNow, the campaign abuses the native POST `/api/now/sp/search?sysparm_cancelable=true` endpoint, used for portal search functionality. If search sources are configured to allow guest access, attackers can enumerate exposed data by varying search terms. Reco highlights that ServiceNow transaction logs do not record POST body content, limiting defenders’ ability to determine the exact search terms used. The volume of requests in one investigated environment increased from tens to hundreds per day.
Reco has not found evidence linking the City-Forum campaign to ShinyHunters, noting that previous campaigns typically used multiple systems and IP addresses, whereas City-Forum’s infrastructure has remained on the same IP since March 2025. The firm advises Salesforce administrators to review guest-user sharing rules, object and field permissions, file access, member visibility, and self-registration settings.
For LWR sites, disabling the Experience Builder option that allows guest access to public APIs is recommended to block enumeration endpoints. ServiceNow administrators should audit exposed search sources and enforce strict authentication for sensitive data access.
The campaign underscores the risks of misconfigured guest access in cloud platforms, with prevention effectiveness declining sharply once attackers gain valid credentials. Reco’s findings align with broader industry concerns about unauthorized data exposure in SaaS environments.
Malaysia Impact
Global development — watch for knock-on effects on oil prices, the ringgit, and KLCI risk sentiment.