highOther

City-Forum Data-Theft Campaign Targeting Salesforce & ServiceNow Portals

First seen Aug 13, 2026 · Updated Aug 13, 2026

data-theftsalesforceservicenowmisconfigurationcustomer-portalexposed-dataanonymous-accesssaas-security

A campaign dubbed 'City-Forum' is using custom tooling to systematically harvest data exposed to anonymous/unauthenticated users through misconfigured Salesforce Experience Cloud sites and ServiceNow customer portals. The attackers exploit overly permissive guest-user access controls rather than a software vulnerability, allowing bulk extraction of sensitive records without authentication.

Technical Analysis

The threat actors leverage misconfigured guest/anonymous user permissions in Salesforce Experience Cloud and similarly permissive ServiceNow customer portal configurations to enumerate and exfiltrate exposed records, likely including case data, customer PII, and support ticket contents. This is a configuration-abuse technique rather than a traditional exploit chain, relying on default or overly broad sharing rules, object permissions, and page layouts that expose internal data to public-facing guest accounts. Custom scraping/automation tools appear to be used to crawl exposed API endpoints and Visualforce/Lightning pages at scale, suggesting reconnaissance-driven, scriptable data harvesting rather than manual browsing. Organizations using AI agents or RAG pipelines that ingest data from these Salesforce/ServiceNow instances (e.g., pulling case histories, KB articles, or customer records into LLM context) could unknowingly expose leaked or attacker-poisoned data to downstream agent workflows, or have agent-accessible API credentials/tokens harvested if stored in exposed configuration objects.

Affected Systems

Salesforce Experience Cloud sites with guest/anonymous user access enabled; ServiceNow customer service portals with public-facing widgets/knowledge bases; instances with overly permissive sharing rules, object/field-level security misconfigurations, or exposed REST/SOAP API endpoints accessible without authentication

Indicators of Compromise

  • No specific hashes, IPs, or domains disclosed in source reporting; custom scraping tool signatures not publicly detailed at time of analysis

Remediation Steps

  1. 1

    Audit guest user permissions

    Review Salesforce Experience Cloud guest user profiles and object/field-level permissions to ensure only intended public data is accessible.

  2. 2

    Restrict ServiceNow portal access

    Review ACLs and public widget configurations on ServiceNow customer portals to eliminate unauthenticated access to sensitive tables and records.

  3. 3

    Enable monitoring and anomaly detection

    Deploy SaaS security posture management (SSPM) tooling to detect unusual bulk data access patterns from anonymous sessions.

  4. 4

    Rotate exposed credentials

    Rotate any API keys, tokens, or credentials that may have been stored in exposed portal configurations or case records.

  5. 5

    Review data ingested into AI/RAG systems

    If Salesforce/ServiceNow data feeds AI agents or RAG pipelines, audit for potential exposure or poisoning of ingested records and validate data provenance.

Industries Most Exposed

retailfinancial serviceshealthcaretechnologytelecommunicationsgovernment

Sources

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.