City-Forum is an unattributed data-theft campaign active since at least March 2025 that targets organizations exposing data through misconfigured Salesforce Experience Cloud and ServiceNow customer portals. The operation is not known to exploit vulnerabilities in either platform; instead, it abuses overly permissive unauthenticated guest-user access, public sharing rules, and exposed portal search or API functionality to enumerate and retrieve records available to anonymous users. Observed targeting spans telecommunications, banking and other financial services, enterprise software, cybersecurity and data privacy companies, and public-sector portals, with victims identified across North America, Europe, and Asia. Activity has been linked to long-lived infrastructure hosted in Germany and to a custom Go-based toolset rather than commodity browser tooling. Researchers observed the same infrastructure and tooling pattern across Salesforce Aura, Salesforce Lightning Web Runtime, and ServiceNow activity, including use of a single multi-platform binary. On Salesforce, City-Forum primarily abuses the Aura framework to enumerate guest-accessible objects and page through exposed records, including common business objects such as accounts, contacts, and cases. The actor also targets newer Lightning Web Runtime deployments through the UI API, including GraphQL and REST-style access paths, and has been observed stepping through multiple Salesforce API versions sequentially. In addition, the campaign probes self-registration functionality to determine whether an unauthenticated visitor can create a more privileged authenticated external account. On ServiceNow, the actor abuses the native Service Portal search capability to enumerate guest-readable content such as knowledge-base and catalog data. The campaign is characterized by high-volume but protocol-legitimate requests, making detection difficult when organizations rely on status codes or endpoint blocking alone. Reported behavior includes sustained enumeration, bulk retrieval of exposed records, and cross-platform reconnaissance of lesser-documented data-access surfaces. Although the tradecraft overlaps superficially with prior Salesforce-focused activity associated with ShinyHunters, City-Forum has not been attributed to any named threat group, and available reporting distinguishes it by its custom multi-platform tooling and inclusion of ServiceNow targeting. The dominant objective is theft of exposed business and customer data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named activity cluster conducting long-running unauthenticated data extraction from misconfigured Salesforce Experience Cloud and ServiceNow customer portals by abusing over-permissive guest identities.
Data theft campaign targeting misconfigured Salesforce Experience Cloud and ServiceNow customer portals by enumerating and extracting data exposed to unauthenticated guest users, including use of Aura framework requests, UI-API GraphQL/REST access, guest-user enumeration, and checks for self-registration paths.
Conducting ongoing data-theft operations against misconfigured Salesforce Experience Cloud and ServiceNow customer portals by abusing anonymous guest access to enumerate and retrieve exposed records.
Long-running data theft campaign targeting Salesforce and ServiceNow instances with overly permissive guest access using a custom toolset and less-documented interfaces to retrieve exposed data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.