These Portal Attacks Are Quietly Stealing Your Customer Data
Michael Miller ·
Listen to this article~4 min
A new data theft campaign called "City-Forum" is using custom tools to steal customer data from Salesforce Experience Cloud and ServiceNow portals. Learn how to protect your business.
There's a new data theft campaign making the rounds, and it's not targeting your average Joe. It's going after businesses that use Salesforce Experience Cloud and ServiceNow customer portals. The scary part? It's using custom tools to grab data that's technically exposed to anonymous users.
If you're running one of these platforms, you need to pay attention. This isn't a theoretical threat or a vague warning from a security vendor trying to sell you something. This is happening right now, and the attackers are getting smarter about how they operate.
### What's Actually Happening Here?
The campaign, which researchers are calling "City-Forum," is using specialized software to scrape and steal information that's available through these portals. Think of it like this: your customer portal is like a storefront with a window display. You want people to see some things, but you don't want them to grab everything off the shelves.
These attackers have figured out how to reach through the window and take more than they should. They're exploiting misconfigurations and overly permissive settings that many companies don't even realize they have enabled.
### Why Should You Care?
If you're using Salesforce Experience Cloud or ServiceNow portals, your customer data is at risk. We're talking about names, email addresses, account details, and potentially even payment information. The types of data that keep compliance officers up at night.
Here's what makes this particularly nasty:
- The tools are custom-built, meaning they're not easily detected by standard security software
- The attacks target anonymous access, so they don't need to break into your system with stolen credentials
- The data being stolen is often considered "public" by your own configuration, making it harder to detect the breach
### The Real Problem: Misconfigured Access Controls
The root cause here isn't necessarily a vulnerability in Salesforce or ServiceNow themselves. It's how companies configure their portals. Many organizations set up these customer portals with broad access permissions to make things easier for users, but that convenience comes at a cost.
When you expose too much data to anonymous users, you're essentially leaving your front door unlocked. The attackers aren't hacking in with sophisticated exploits. They're simply walking through the open door and taking what's available.
### What You Can Do Right Now
Don't panic, but do take action. Here's a practical approach to protecting your data:
1. **Audit your portal permissions** - Go through every single setting and question whether anonymous users really need that level of access
2. **Review your data exposure** - Check what fields and records are visible to users who aren't logged in
3. **Monitor for unusual traffic** - Look for patterns like rapid-fire requests or downloads of large data sets
4. **Implement rate limiting** - This can slow down automated scraping tools significantly
5. **Work with your security team** - Make sure they're aware of this campaign and checking your logs for indicators of compromise
### The Bottom Line
This campaign is a wake-up call for anyone running customer portals. The tools are getting more sophisticated, but the underlying problem is often simple: too much access, too little oversight.
Take the time this week to review your portal configurations. It could save you from a massive headache down the road. And if you're not sure whether your setup is secure, get a professional to look at it. The cost of prevention is always cheaper than the cost of a breach.
Stay safe out there, and remember: just because you can expose data doesn't mean you should.