"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
AI Summary
The City-Forum data theft campaign targets misconfigured Salesforce Experience Cloud and ServiceNow portals by exploiting overly permissive guest user access. Attackers use a single server at IP 158.220.87.79 to enumerate and steal data exposed to unauthenticated users via custom techniques on both legacy Aura and newer Lightning Web Runtime (LWR) frameworks in Salesforce, as well as the ServiceNow Service Portal search API. The campaign has been active since at least March 2025, with increasing activity across multiple sectors including finance, telecom, and public-sector organizations. No vulnerability is exploited; instead, the theft relies on misconfigurations that allow public access to sensitive records.
AI-extracted · verify before operational use