THE 'City-Forum' campaign has been targeting Salesforce and ServiceNow from March 2025, employing a custom toolset to exploit overly permissive guest access for data theft across various sectors, including finance and telecommunications. Researchers from Reco highlighted the campaign's innovative approach, noting the threat actor's development of unique techniques to identify data vulnerabilities, particularly in Salesforce's new Lightning Web Runtime.
This campaign is more sophisticated than usual, involving extensive research on weak points rather than relying solely on public tools. Recommendations for mitigation include auditing guest-user permissions and tightening access controls on both platforms to prevent unauthorized data access. The campaign has impacted organizations globally, particularly in North America, Europe, and Asia.