Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label City-Forum Campaign. Show all posts

City-Forum Campaign Puts Salesforce and ServiceNow Portals at Risk


City-Forum is a year- plan aimed at stealing data from organizations that have weak Salesforce Experience Cloud and ServiceNow customer portals. Special tools are used to get data that can be seen by people who are not identified. This campaign is watched by the SaaS security company Reco. It has affected companies in telecommunications, financial services, enterprise software, cybersecurity, data privacy and the public sector. 

The activity is getting worse over time. Several researchers have found one server and a setup that has been working since March 2025. This is where the attacks come from. By using weaknesses in Salesforce or ServiceNow the attackers are using data that companies accidentally made visible. This happens when they create guest accounts with much access or not enough sharing settings. 

The attack does not need a weakness in Salesforce or ServiceNow. Salesforce has seen activity that mainly uses the Aura framework. This framework makes requests to find records that can be seen by people who are not logged in. Then it gets data from these exposed objects. 

Reliability found the attack pattern, on both platforms and many companies. This shows that the attackers are using a custom tool of a regular software. It includes listing Salesforce objects like Accounts, Contacts and Cases and then trying to access the records. 

A focused environment recorded over 560,000 instances coming from its IP address mostly linked to guest-user enumerations. The guest account remains a part of the attack path. Both Salesforce Experience Cloud and ServiceNow use guest users for access without authentication which means that wrong settings or sharing rules could let records be seen by requests from the internet. 

The project also looks into Salesforce self-registration, which might give attackers a way to go past the permissions given to guest users. Reco watched requests to /SiteRegister. On most of the found Experience Cloud sites to check if self-registration was turned on. When it was possible the feature could allow a guest to create a verified account with more access than the unknown profile. 

In Salesforce LWR environments the attackers used a way. Using the Aura endpoint the campaign aimed at the platform’s UI-API through its GraphQL and REST interfaces. The tool is said to have checked API versions one after another but LWR activity stayed much lower than the number of Aura-based requests. 

The way people can see things on each website is different. Sometimes when people who are not employees look at Salesforce they can see things that are not meant for them like customer information help requests, calendar events and emails. With ServiceNow people can usually only see things like guides and instructions. This is because each company can set up ServiceNow in its own way so what people can see and how important it is can be very different from one company to another. 

Reco does not think that City-Forum is the same as ShinyHunters even though they do some things in the way when it comes to Salesforce. City-Forum is different from groups because it uses the same computers and internet addresses all the time. When researchers looked at logs from customers they saw that companies in North America, Europe and Asia were being targeted and most of the time it was Salesforce that was being used. 

To stay safe companies need to look at who can see what on their websites by just thinking that the problem is with the website itself. People in charge of Salesforce need to check things like what guests can see, who can get to what information and who can join the site and they need to turn off any parts of the site that do not need to be open to the public.

People in charge of ServiceNow need to look at what search results people can see when they visit the site and make sure that important information is protected with passwords and other security measures. Reco has also made public some signs that a bad thing is happening and some tips on how to spot this thing in Salesforce Event Monitoring and ServiceNow transaction logs. 

If users see one of these signs it does not mean for sure that some important information has been stolen. It is a good idea to look into what is going on. The City-Forum people are saying that if users’ do not pay attention to what visitors can do on their site they might be in trouble. Organizations need to check their settings and make sure that visitors can not get to things they should not be able to get to. They also need to watch out for things happening on Salesforce and ServiceNow.