Researchers at Reco have documented a campaign called City-Forum that has been pulling records from Salesforce and ServiceNow portals worldwide since at least March 2025. Named after a domain registered in 2002, the operation requires no exploit and no credentials: attackers simply visited public customer portals as anonymous guest users and asked for their contents.
None of the requests Reco observed carried credentials; all arrived as guest traffic. The victim list spans telecom, banking, financial services, software vendors, and public-sector portals. One heavily hit target logged over 560,000 events from the single address, nearly all of it Aura-framework enumeration on Salesforce’s legacy stack.
The operator also built custom tooling aimed at two areas existing attack tools ignore: the data layer behind Salesforce’s newer site framework and an undocumented ServiceNow portal search endpoint. Reco’s Nitay Bachrach said the most frequent root cause on both platforms was over-permissioned guest and anonymous accounts, and flagged Salesforce guest sharing rules as the highest-impact fix.
Audit logs show what was attempted, not what was taken, so organizations must simulate the requests internally to gauge exposure. The operator has held a single infrastructure address for 17 months with no rotation, an unusual fingerprint for these campaigns.
