Executive Summary
Since at least March 2025, an unidentified threat actor has been conducting a prolonged data theft campaign, dubbed "City-Forum," targeting organizations across various sectors by exploiting overly permissive guest access in Salesforce and ServiceNow platforms. The attacker developed custom tools to interact with less-documented interfaces, such as Salesforce's Lightning Web Runtime and ServiceNow's Service Portal search endpoint, enabling unauthorized access to sensitive data including customer information, support tickets, and internal communications.
This incident underscores the evolving sophistication of cyber threats, highlighting the need for organizations to reassess and fortify their security configurations, especially concerning third-party integrations and guest access permissions. The campaign's duration and the attacker's ability to exploit undocumented interfaces emphasize the importance of continuous monitoring and proactive security measures.
Why This Matters Now
The "City-Forum" campaign exemplifies the increasing sophistication of cyber threats, emphasizing the urgent need for organizations to reassess and strengthen their security configurations, particularly concerning third-party integrations and guest access permissions. The attacker's ability to exploit undocumented interfaces highlights the importance of continuous monitoring and proactive security measures.
Attack Path Analysis
The 'City-Forum' campaign began with attackers exploiting misconfigured guest access in Salesforce and ServiceNow platforms to gain unauthorized entry. They then escalated privileges by leveraging these misconfigurations to access sensitive data. The attackers conducted reconnaissance to identify and access additional data repositories within the compromised environments. They established command and control by maintaining persistent access through the exploited misconfigurations. Data exfiltration was carried out by extracting sensitive information from the platforms. The impact included unauthorized access to customer data, leading to potential privacy violations and reputational damage.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited misconfigured guest access in Salesforce and ServiceNow platforms to gain unauthorized entry.
Related CVEs
CVE-2026-6875
CVSS 9.5A critical remote code execution vulnerability in ServiceNow's AI Platform sandbox allows unauthenticated attackers to execute arbitrary code on vulnerable instances.
Affected Products:
ServiceNow AI Platform – Affected versions prior to July 13, 2026
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Exploit Public-Facing Application
Data from Cloud Storage
Automated Exfiltration
Application Layer Protocol
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Restrict access to system components and cardholder data
Control ID: 7.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity and Access Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
High-value customer data exposure through Salesforce guest access vulnerabilities, with potential Social Security numbers, financial data, and credit card information theft.
Telecommunications
Specifically targeted by City-Forum campaign with custom toolset exploiting ServiceNow and Salesforce misconfigurations, exposing customer records and service data.
Computer Software/Engineering
Enterprise software companies directly targeted, with Salesforce LWR runtime exploitation exposing development data, customer information, and proprietary technical documentation.
Computer/Network Security
Security firms compromised despite expertise, highlighting advanced threat actor capabilities using custom tools to bypass traditional detection methods and access controls.
Sources
- Long-running Data Theft Campaign Targeting Salesforce, ServiceNowhttps://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenowVerified
- Overly permissive ‘guest’ settings put Salesforce customers at riskhttps://www.csoonline.com/article/4143667/overly-permissive-guest-settings-put-salesforce-customers-at-risk.htmlVerified
- ServiceNow Says a REST API Bug Left Customer Data Reachable Without Logging Inhttps://breached.company/servicenow-unauthenticated-api-customer-data-exposure-2026/Verified
- Protecting Your Data: Essential Actions to Secure Experience Cloud Guest User Accesshttps://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/?bc=OTHVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit unauthorized access and lateral movement within cloud environments, thereby reducing the attacker's ability to escalate privileges and exfiltrate sensitive data.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit misconfigured guest access would likely be constrained, reducing the risk of unauthorized entry into cloud platforms.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the risk of unauthorized access to sensitive data.
Control: East-West Traffic Security
Mitigation: The attacker's ability to move laterally within the cloud environment would likely be constrained, reducing the risk of accessing additional data repositories.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to maintain persistent access would likely be constrained, reducing the risk of prolonged unauthorized presence.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the risk of data loss.
The attacker's ability to cause significant impact would likely be constrained, reducing the risk of extensive privacy violations and reputational damage.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management (CRM)
- IT Service Management (ITSM)
- Data Privacy Compliance
Estimated downtime: 7 days
Estimated loss: $5,000,000
Personally identifiable information (PII) of customers, including names, contact details, and potentially sensitive business data.
Recommended Actions
Key Takeaways & Next Steps
- • Review and correct guest-user sharing rules to ensure anonymous users have minimal access.
- • Disable unnecessary permissions on guest profiles to prevent unauthorized data access.
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement.
- • Utilize Multicloud Visibility & Control to monitor and detect anomalous interactions across cloud platforms.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.



