Canadian Cyber Security Journal
SOCIAL:
Filed under: Trends

City-Forum Campaign Quietly Scraped Salesforce and ServiceNow Portals for Over a Year

What Happened

Researchers documented a long-running data-theft campaign, dubbed City-Forum, harvesting records from Salesforce Experience Cloud and ServiceNow Service Portal deployments worldwide since at least March 2025. The campaign exploits no software vulnerability. Instead, it abuses overly permissive guest-user sharing settings organizations configure themselves, pulling data through Salesforce’s UI-API guest surface, the first observed in-the-wild abuse of the interface, and through ServiceNow’s native POST /api/now/sp/search endpoint when portals accept anonymous search requests. Every observed request traces to a single IP address hosted by German provider Contabo and tied to the domain city-forum.com, using the default Go-http-client user agent throughout. Researchers say the operator built a custom toolset targeting both the older Salesforce Aura framework and the newer LWR implementation, and the infrastructure stayed active and undetected for over a year before disclosure. Telecoms, banks, financial-services firms, enterprise software and data-privacy vendors, and public-sector portals rank among the primary targets identified so far.

Why This Matters for Canadian Organizations

Salesforce and ServiceNow run customer-facing and public-sector portals across Canadian banks, telecoms, provincial and federal government services, and enterprise vendors, often with guest-access features enabled for legitimate self-service functions. The City-Forum campaign shows attackers actively scanning for exactly this kind of permissive configuration, and because no vulnerability needs patching, standard vulnerability management programs miss the exposure entirely. Data exposed through guest-access misconfiguration on a Canadian government or financial-services portal falls squarely under PIPEDA breach-notification obligations, and OSFI-regulated institutions face configuration-review expectations under Guideline B-13 extending to third-party SaaS platforms, not only internally hosted systems.

What to Do

Salesforce and ServiceNow administrators should audit guest-user sharing rules and object permissions now, restricting anonymous access to only the fields and objects a public-facing use case genuinely requires. Review portal access logs for requests originating from 158.220.87.79 or the Go-http-client user agent pattern, and disable the ServiceNow sp/search anonymous endpoint where guest search access is not in active use. Full technical detail is available from SecurityWeek and BleepingComputer.

Enjoy this article? Don’t forget to share.