A sophisticated cyber campaign has been identified, targeting Salesforce Experience Cloud and ServiceNow Service Portals on a global scale. Known as the ‘City-Forum Campaign’, this operation has been active since at least March 2025, affecting a wide range of industries, including telecommunications, financial services, and public sector organizations.
City-Forum Campaign Unveiled
The City-Forum Campaign, linked to a domain associated with the attackers, has been quietly extracting data from critical cloud platforms. Unlike other cybercrime entities such as ShinyHunters, this group has developed a more intricate technique that goes beyond exploiting Salesforce’s legacy Aura framework.
By leveraging both high-volume Aura enumeration and targeting Salesforce’s newer Lightning Web Runtime (LWR) sites, the attackers exploit a lack of public tools and documentation in the UI-API data layer. Simultaneously, they have identified an undocumented search endpoint within ServiceNow Service Portals, further broadening their attack surface.
Techniques and Indicators
Reco researchers point out that the attack reflects a well-planned strategy by operators who have extensively researched both Salesforce and ServiceNow platforms to identify potential data leakage points. The attacks originate from a single IP address, 158.220.87[.]79, hosted on a Contabo VPS in Germany.
Significant indicators of this operation include the use of a custom user-agent, Go-http-client/1.1, signifying an automated Go-based application. The attackers have maintained a static IP and domain presence, departing from the usual practice of using rotating proxies in such campaigns.
Impact and Defensive Measures
This campaign has managed to harvest enterprise information without resorting to traditional exploit payloads. The adversaries employ Google dorking techniques to map organizational perimeters before executing automated data extraction processes.
For Salesforce environments, it is crucial to review guest sharing rules and limit object and field-level permissions. Disabling self-registration and public API access within Experience Builder is recommended. In ServiceNow environments, auditing search sources and adjusting Knowledge Base access criteria can mitigate exposure.
Reco’s research emphasizes that the campaign exploits overly permissive configurations rather than zero-day vulnerabilities, urging organizations to reassess their security practices.
By understanding and addressing these vulnerabilities, companies can better secure their cloud infrastructure against sophisticated threats like the City-Forum Campaign.
