Threats · 41 days ago
Reco says the City Forum campaign has been harvesting Salesforce Experience Cloud and ServiceNow guest portals for more than a year from one VPS at 158.220.87.79, and day 6 of the reporting now ties that activity to a single long-lived Go-based scraper. The targets Reco identified span telecom, financial services, technology, and public-sector portals.
The scraper logs in as the built-in guest user those portals already expose, then pages through whatever that identity can read. Because the guest account is persistent and cannot be deleted, the exposure sits in the portal’s public-read design: if guest access is too broad, records can be pulled repeatedly without any internal network compromise or admin takeover.
That shifts the story from a loose series of intrusions to a standing harvest of public-facing records across industries. For teams that publish data through guest portals, the open question is not whether the attacker got inside, but how much of the site was readable to a visitor all along.
5 sources covering this story
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
City Forum uses one server to pull records from over-permissive Salesforce and ServiceNow guest portals across industries for over a year.
Long-running Data Theft Campaign Targets Salesforce, ServiceNow
The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors.
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals.
Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign
Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms.
Part of the PlainSec briefing for 2026-08-18