Executive Summary

Since at least March 2025, an unidentified threat actor has been conducting a prolonged data theft campaign, dubbed "City-Forum," targeting organizations across various sectors by exploiting overly permissive guest access in Salesforce and ServiceNow platforms. The attacker developed custom tools to interact with less-documented interfaces, such as Salesforce's Lightning Web Runtime and ServiceNow's Service Portal search endpoint, enabling unauthorized access to sensitive data including customer information, support tickets, and internal communications.

This incident underscores the evolving sophistication of cyber threats, highlighting the need for organizations to reassess and fortify their security configurations, especially concerning third-party integrations and guest access permissions. The campaign's duration and the attacker's ability to exploit undocumented interfaces emphasize the importance of continuous monitoring and proactive security measures.

Why This Matters Now

The "City-Forum" campaign exemplifies the increasing sophistication of cyber threats, emphasizing the urgent need for organizations to reassess and strengthen their security configurations, particularly concerning third-party integrations and guest access permissions. The attacker's ability to exploit undocumented interfaces highlights the importance of continuous monitoring and proactive security measures.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The campaign highlighted vulnerabilities in guest access configurations and insufficient monitoring of third-party integrations, leading to unauthorized data access.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit unauthorized access and lateral movement within cloud environments, thereby reducing the attacker's ability to escalate privileges and exfiltrate sensitive data.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's ability to exploit misconfigured guest access would likely be constrained, reducing the risk of unauthorized entry into cloud platforms.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges would likely be constrained, reducing the risk of unauthorized access to sensitive data.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's ability to move laterally within the cloud environment would likely be constrained, reducing the risk of accessing additional data repositories.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's ability to maintain persistent access would likely be constrained, reducing the risk of prolonged unauthorized presence.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's ability to exfiltrate sensitive data would likely be constrained, reducing the risk of data loss.

Impact (Mitigations)

The attacker's ability to cause significant impact would likely be constrained, reducing the risk of extensive privacy violations and reputational damage.

Impact at a Glance

Affected Business Functions

  • Customer Relationship Management (CRM)
  • IT Service Management (ITSM)
  • Data Privacy Compliance
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Personally identifiable information (PII) of customers, including names, contact details, and potentially sensitive business data.

Recommended Actions

  • Review and correct guest-user sharing rules to ensure anonymous users have minimal access.
  • Disable unnecessary permissions on guest profiles to prevent unauthorized data access.
  • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement.
  • Utilize Multicloud Visibility & Control to monitor and detect anomalous interactions across cloud platforms.
  • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image