The "City-Forum" campaign is exploiting misconfigured Salesforce and ServiceNow portals to steal exposed customer data. Learn how the attacks work and what you can do to protect your organization.
If you're managing customer portals, here's something that should keep you up at night. A new wave of attacks called "City-Forum" is actively stealing data from Salesforce Experience Cloud and ServiceNow customer portals. And the scary part? The attackers aren't breaking in through complex exploits. They're simply taking what's already exposed to anonymous users.
This isn't some theoretical threat or a vague warning from a security vendor. It's an ongoing campaign with custom-built tools designed to do one thing: harvest data that companies accidentally left sitting in plain sight. Let's break down what's happening, why it matters, and what you can do about it.
### The Anatomy of the Attack
The attackers behind "City-Forum" have figured out something important. Many organizations configure their Salesforce and ServiceNow portals to allow anonymous access for certain features. That could be a knowledge base, a case submission form, or a customer self-service page. But sometimes, those same portals expose far more than intended.
What makes this campaign different is the level of automation. The bad guys aren't manually clicking through pages. They're using custom scripts that systematically scan for exposed data, pull it out, and move on. It's fast, it's quiet, and it's effective.
Here's what typically gets targeted:
- Customer records with personal information
- Case details and support history
- Internal notes that were never meant to be public
- API endpoints that shouldn't be accessible without authentication
### Why This Is Happening Now
You might be wondering why this is suddenly a big deal. The truth is, portal misconfigurations have been around for years. What's changed is the tooling. Attackers now have access to automated frameworks that can scan thousands of portals in minutes, looking for the same types of misconfigurations.
The "City-Forum" campaign takes advantage of the fact that many teams assume their portal is locked down. They set up a community page, enable guest access, and move on. But guest access is a double-edged sword. If you don't carefully review what anonymous users can see, you're handing over your data on a silver platter.
### The Real Cost of Ignoring This
Let's talk about what's at stake. A data breach from a portal misconfiguration isn't just an IT headache. It's a regulatory nightmare, a customer trust killer, and potentially a huge financial hit. In the United States, the average cost of a data breach is around $4.45 million, according to IBM's latest report. But that's just the average. For a company with sensitive customer data, the real cost can be much higher.
Beyond the fines and legal fees, there's the reputational damage. When customers find out their personal information was exposed because of a simple configuration error, they don't stick around. They leave, and they tell their friends.
### How to Protect Your Portals
So, what can you actually do about this? The good news is that protecting yourself doesn't require a massive security overhaul. It requires a little discipline and a few simple checks.
**Audit your anonymous access settings.** Log into your Salesforce or ServiceNow admin console and review exactly what anonymous users can see. If you don't need a specific page or object to be publicly accessible, turn it off.
**Test your portals like an attacker would.** Use a fresh browser session, log out, and try to access sensitive pages. Look for anything that shouldn't be visible. If you can see it, so can the bad guys.
**Set up monitoring for unusual data access patterns.** If you see a sudden spike in API calls from a single IP address, that's a red flag. Most portal platforms have logging features that can help you catch this early.
**Review your third-party integrations.** Sometimes the issue isn't in the portal itself, but in a connected app that has broader permissions than it needs. Check every integration and make sure it follows the principle of least privilege.
### The Bottom Line
Here's the thing: the "City-Forum" campaign isn't going away anytime soon. It's a reminder that in the world of cybersecurity, the simplest mistakes often lead to the biggest problems. Your customer portal is a front door, and if you leave it unlocked, someone will walk in.
The good news is that you have the power to prevent this. Take a few hours this week to review your portal configuration. Test it from the outside. Ask yourself: if I were an attacker, could I get to this data? If the answer is yes, fix it now.
Because the alternative is waiting for a breach notification to be sent to your customers, and that's a conversation nobody wants to have.