Recent research by Reco has highlighted a sophisticated cyber attack campaign, dubbed ‘City-Forum’, targeting major platforms Salesforce and ServiceNow. This campaign employs a unique multi-platform toolset, raising concerns within the telecom, financial services, enterprise software, and public sector industries.
Targeted Platforms and Techniques
The ‘City-Forum’ campaign focuses on Salesforce’s Aura and LWR implementations, marking the first known in-the-wild exploitation of Salesforce’s UI-API guest interface. The attacks involve custom tools that simultaneously target both Salesforce and ServiceNow, indicating a high level of innovation and planning.
According to researchers, the attacks leverage the Guest User feature in Salesforce Experience Cloud and ServiceNow. These guest accounts allow unauthenticated requests, posing a significant risk as they cannot be deleted, and their permissions and sharing rules remain active. This vulnerability potentially exposes sensitive data if misconfigured.
Comparative Analysis with Previous Campaigns
In comparison to previous attacks, such as the ShinyHunters’ campaign in March 2026 which solely targeted Salesforce’s Aura, ‘City-Forum’ uses a novel custom multi-platform toolset. Unlike ShinyHunters, which modified existing tools, this campaign introduces entirely new methodologies, also affecting ServiceNow through an under-documented search endpoint.
Reco’s analysts speculate on the origin of these attacks but have not confirmed any links to ShinyHunters or other known groups. The persistent use of a single IP address since March 2025 suggests a strategic approach, minimizing the footprint to evade detection by anomaly systems.
Security Concerns and Recommendations
The ‘City-Forum’ attacks highlight the importance of securing guest user access. While current activities have not involved authenticated users, the possibility remains if self-registration is enabled. Organizations are advised to disable this feature as a precautionary measure.
Exfiltration of data from both Salesforce and ServiceNow is conducted in a stealthy manner, utilizing legitimate protocols. This reinforces the need for vigilant monitoring and robust security practices. Detailed indicators of compromise and remediation steps are available in the Reco research blog, providing guidance on mitigating these risks.
In conclusion, while no breaches of the core Salesforce or ServiceNow platforms have been reported, the exposure of data accessible to anonymous users underscores the critical need for comprehensive security measures. Organizations must remain alert to these sophisticated threats, ensuring configurations are tightened and access controls are rigorously enforced.
