Executive Summary
Since March 2025, a single attacker has systematically scraped data from Salesforce and ServiceNow customer portals across various industries, including telecommunications, financial services, and public sector organizations. The attacker utilized a server (IP: 158.220.87.79) hosted by Contabo, employing a custom tool identified by the Go net/http library's default user agent. This tool exploited misconfigured guest user profiles, allowing unauthorized access to sensitive records without authentication. The campaign, dubbed 'City Forum,' highlights the critical need for organizations to review and tighten guest user permissions to prevent unauthorized data access. (reco.ai)
This incident underscores a growing trend of attackers targeting misconfigured SaaS platforms to exfiltrate data. As organizations increasingly rely on cloud-based services, ensuring proper configuration and access controls becomes paramount to safeguard sensitive information.
Why This Matters Now
The 'City Forum' campaign exemplifies the escalating threat posed by attackers exploiting misconfigured SaaS platforms. With the proliferation of cloud services, organizations must prioritize securing guest user access to prevent unauthorized data exfiltration. Immediate action is required to audit and rectify access controls, mitigating potential breaches and safeguarding sensitive information.
Attack Path Analysis
An attacker exploited misconfigured guest user permissions in Salesforce and ServiceNow portals to access and exfiltrate sensitive data. The attack involved unauthorized data scraping using a custom tool, leading to significant data exfiltration.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
The attacker identified and exploited misconfigured guest user permissions in Salesforce and ServiceNow portals, allowing unauthorized access to sensitive data.
Related CVEs
CVE-2025-3648
CVSS 8.2A high-severity vulnerability in ServiceNow's platform allows attackers to exploit the record count UI element on list pages, using enumeration techniques and query filters to infer and expose sensitive data from various tables.
Affected Products:
ServiceNow ServiceNow Platform – All versions prior to the patch released in September 2024
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Data from Information Repositories: Customer Relationship Management Software
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Exfiltration Over Web Service: Exfiltration Over Webhook
Valid Accounts
Brute Force
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Restrict access to system components and cardholder data
Control ID: 7.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Implement strong authentication and authorization mechanisms
Control ID: Identity and Access Management
NIS2 Directive – Security Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Financial Services
Banks and financial firms face severe data exfiltration risks from Salesforce/ServiceNow guest access abuse, compromising customer records and regulatory compliance requirements.
Telecommunications
Telecom companies experience direct targeting through SaaS portal scraping, exposing customer data and network infrastructure details via misconfigured guest permissions.
Computer Software/Engineering
Software vendors including security companies suffer reputational damage from data breaches through automated scraping of their own Salesforce and ServiceNow platforms.
Government Administration
Public sector portals face persistent automated attacks extracting sensitive citizen data through overprivileged guest accounts across multiple government service platforms.
Sources
- One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025https://thehackernews.com/2026/08/one-attacker-has-scraped-both.htmlVerified
- Overly permissive ‘guest’ settings put Salesforce customers at riskhttps://www.csoonline.com/article/4143667/overly-permissive-guest-settings-put-salesforce-customers-at-risk.htmlVerified
- Protecting Your Data: Essential Actions to Secure Experience Cloud Guest User Accesshttps://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/?bc=OTHVerified
- An Advanced Attacker Is Targeting Salesforce and ServiceNowhttps://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow?utm_source=hackernewsVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Implementing Aviatrix Zero Trust CNSF would likely have constrained the attacker's ability to exploit misconfigured permissions and exfiltrate sensitive data by enforcing strict access controls and segmenting network traffic.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's ability to exploit misconfigured permissions would likely have been constrained, reducing unauthorized access to sensitive data.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges would likely have been constrained, limiting access to sensitive data.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement within the network would likely have been constrained, reducing the scope of accessible data.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels would likely have been constrained, reducing automated data extraction.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts would likely have been constrained, reducing the volume of data exfiltrated.
The overall impact of the attack would likely have been constrained, reducing potential data breaches and associated consequences.
Impact at a Glance
Affected Business Functions
- Customer Relationship Management (CRM)
- IT Service Management (ITSM)
- Data Privacy Compliance
Estimated downtime: N/A
Estimated loss: N/A
Potential exposure of sensitive customer and business data, including personally identifiable information (PII) and credentials.
Recommended Actions
Key Takeaways & Next Steps
- • Review and restrict guest user permissions to enforce least privilege access.
- • Implement Zero Trust Segmentation to isolate sensitive data and limit unauthorized access.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound data flows.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities across cloud environments.
- • Conduct regular audits and apply Threat Detection & Anomaly Response mechanisms to identify and mitigate potential threats.



