The "City-Forum" Attacks That Are Emptying Salesforce and ServiceNow Portals

·
Listen to this article~4 min

A data theft campaign called "City-Forum" is using custom tools to steal exposed data from Salesforce and ServiceNow customer portals. Learn how to protect your business before it's too late.

If you run a customer portal on Salesforce or ServiceNow, here's something that should keep you up at night: a new wave of data theft is quietly picking off businesses that thought their portals were locked down tight. The campaign, nicknamed "City-Forum" by researchers, isn't your run-of-the-mill phishing attempt. It uses custom-built tools to scoop up data that's been exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. Think of it like a burglar who doesn't break a window—they just walk through the front door because someone left it cracked. ### What's Actually Happening Here's the uncomfortable truth: many organizations set up these portals for convenience. Customers log in, submit tickets, check order statuses, download files. But somewhere along the line, permissions get misconfigured. Maybe a field that should be private is marked public. Maybe an API endpoint is left open. And that's all the attackers need. The "City-Forum" crew uses custom scripts and tools to scan for these gaps, then pulls whatever data is accessible without any authentication. We're talking about customer records, support histories, internal notes, and potentially sensitive documents that were never meant to see the light of day. ### Why This Feels Different This isn't a spray-and-pray operation. The attackers are methodical. They've built tools specifically for these platforms, which means they know the ins and outs of how Salesforce and ServiceNow handle data. That level of preparation suggests they've been studying these systems for a while. It also means the usual advice—"just update your software"—won't cut it. The vulnerability isn't in the code itself; it's in how the portals are configured and managed. And that's a much harder problem to solve. ### How to Protect Your Portal If you're running one of these portals, don't wait for a breach notification to start caring. Here's what you can do right now: - **Audit your public-facing pages.** Log out of your portal and browse it as a stranger would. Click through every page, every form, every file download. If you can see it, so can they. - **Review your permission settings.** Go through every object, field, and record type. Ask yourself: does this really need to be visible to anonymous users? If not, lock it down. - **Check your API endpoints.** Many of these attacks rely on exposed APIs. Make sure every endpoint requires proper authentication and that you're not accidentally exposing data through undocumented calls. - **Monitor your logs.** Look for unusual traffic patterns—repeated requests, rapid-fire queries, or access from unexpected IP ranges. Early detection can stop an attack before it becomes a headline. ### The Bottom Line "City-Forum" is a wake-up call for anyone who's been treating their customer portal as a low-risk asset. The reality is that any data you expose online—even behind what you think is a secure login—is a potential target. The good news? You don't need to be a security wizard to close the gaps. You just need to be thorough. Take a weekend to audit your setup. Bring in a fresh pair of eyes if you can. And if you find something that shouldn't be public, fix it immediately. Because the next attacker knocking on your portal's door might not be as polite as this one.