A sophisticated and long-running data theft campaign, named 'City-Forum' by Reco, is actively targeting organizations by exploiting common misconfigurations in their Salesforce Experience Cloud and ServiceNow portals. Active since at least March 2025, the campaign does not leverage a vulnerability in the SaaS platforms themselves, but rather capitalizes on overly permissive guest user access settings configured by customers. The threat actor uses a custom toolset to enumerate and exfiltrate sensitive data exposed to anonymous users. The campaign is notable for its advanced methodology, including a novel technique for scraping data from modern Salesforce Lightning Web Runtime (LWR) sites, and has impacted a wide range of industries globally.
The 'City-Forum' campaign is orchestrated by a single threat actor operating from the IP address 158.220.87.79 (hosted by Contabo in Germany). The attacks are systematic and automated, targeting public-facing SaaS portals.
The actor demonstrates a deep understanding of the targeted SaaS platforms.
Salesforce Attacks:
ServiceNow Attacks:
This is a data theft campaign (T1530) focused on reconnaissance and collection, likely to sell the data or use it for further attacks.
Organizations that misconfigure their SaaS portals are at risk of significant data leakage. The exposed data can include customer PII, internal support tickets, knowledge base articles with sensitive information, and other business data. This can lead to regulatory fines (e.g., under GDPR or CCPA), reputational damage, and provide intelligence for more targeted follow-on attacks like spear-phishing. The stealthy nature of the attacks, especially on ServiceNow where search terms aren't logged for guests, means a breach could go unnoticed for a long time, and its full scope may never be known.
158.220.87.79city-forum.comSecurity teams should hunt for the following patterns:
/s/sfsites/aura, /s/sfsites/lwc/api/now/sp/search158.220.87.79) or other suspicious sources.Regularly audit and harden the configurations of SaaS platforms, paying special attention to guest user permissions and data sharing rules.
Mapped D3FEND Techniques:
Implement comprehensive logging for SaaS platforms and analyze logs for anomalous access patterns, even from unauthenticated users.
Mapped D3FEND Techniques:
Block known malicious IP addresses associated with attackers to prevent reconnaissance and exploitation attempts.
The 'City-Forum' campaign is assessed to have been active since at least this date.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.