Researchers have identified a stealthy campaign dubbed City-Forum that is harvesting data from Salesforce Experience Cloud sites and ServiceNow Service Portals by abusing overly permissive anonymous guest access rather than exploiting a platform vulnerability. The activity has reportedly been ongoing since at least March 2025 and has targeted organizations in telecommunications, banking and financial services, enterprise software, and the public sector. Investigators said the actor uses a custom multi-platform toolset, including a single Go-based binary, to enumerate Salesforce Aura, Lightning Web Runtime, and ServiceNow environments and exfiltrate information that victims had already exposed to unauthenticated users.
The campaign is notable for what researchers described as the first observed in-the-wild exploitation of Salesforce's UI-API guest surface, including GraphQL-based queries across versions v56.0 to v66.0, while ServiceNow targeting includes the undocumented /api/now/sp/search endpoint to retrieve readable knowledge base and catalog content. Activity was tied to the IP address 158.220.87.79, associated with city-forum.com, with requests reportedly using the Go-http-client/1.1 user agent from a Contabo-hosted VPS in Germany. Researchers said they found no evidence of a breach in Salesforce or ServiceNow themselves, but warned that misconfigurations such as self-registration and excessive guest permissions could allow broader access and urged defenders to audit public portals, restrict guest capabilities, and review logs for the identified indicators.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Reco compared City-Forum with a separate ShinyHunters campaign that was disclosed in March 2026. According to the researchers, that earlier activity targeted Salesforce Aura only and had no known ServiceNow targeting.
Researchers said the campaign's infrastructure, including the domain city-forum.com, had been associated with the same IP address 158.220.87.79 since March 2025. They observed the operator continuing to use that single machine over an extended period instead of rotating infrastructure.
Researchers said the City-Forum activity has been active since at least March 2025, harvesting data from exposed guest-access surfaces in Salesforce Experience Cloud and ServiceNow Service Portals. The campaign relied on permissive anonymous access rather than exploiting vulnerabilities in either platform.
Reco disclosed the City-Forum campaign as a stealthy operation using a custom multi-platform Go-based toolset to enumerate and exfiltrate data from Salesforce Aura, Salesforce LWR, and ServiceNow guest-access surfaces. The researchers described it as the first observed in-the-wild exploitation of Salesforce's UI-API guest surface and said they could not attribute the activity to a specific actor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourcedarkreading.com
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcereco.ai
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.