An unknown threat actor has spent more than a year systematically harvesting data from Salesforce and ServiceNow portals around the world, collecting information that organizations accidentally exposed to unauthenticated visitors. Researchers at Reco have dubbed the operation "City-Forum" after a domain tied to its infrastructure, according to findings published this week. The campaign has been active since at least March 2025 and continues to escalate in intensity, targeting telecoms firms, banks, financial services companies, enterprise software providers, cybersecurity organizations, and government agencies.
The busiest Salesforce target alone recorded more than 560,000 events from the attacker's IP address during the campaign, nearly all of them attempts to catalog data available to guest users. On Salesforce, the operation focuses on Lightning Web Runtime sites through the UI API's GraphQL layer, a technique Reco says hasn't been documented in public research or built into publicly available attack tools. Over at ServiceNow, the same operator queries a native Service Portal search endpoint that has received minimal public scrutiny. The attacker's custom toolset also probes whether Salesforce sites allow self-registration, potentially opening a path from anonymous guest access to an authenticated external account with permissions to view substantially more data. Reco observed these self-registration checks across the majority of Salesforce targets it examined. Unusually, the operation hasn't altered its infrastructure: the same IP address and domain have remained in use for at least 17 months, with related custom tools circulating across both platforms.
"The threat actor created their own toolset, based on research and techniques which are not well documented online," said Nitay Bachrach, senior security researcher at Reco. "They studied the services to map different common data leak vectors—this is an advanced actor." Reco linked the Salesforce and ServiceNow activity to the same server, which hit multiple organizations globally. The researchers aren't attributing the campaign to ShinyHunters or any other known group, with Bachrach stating the team isn't ruling anyone in or out. All the activity Reco observed was conducted without authentication, with the attacker gathering information that organizations had left open through permissions, sharing rules, search sources, or other configuration decisions.
This operation exploits a reality that's distinct from a platform flaw: if guest accounts can read a record, anyone on the internet can too, Bachrach warned. The issue stems from over-permissioned guest access rather than software vulnerabilities in Salesforce or ServiceNow themselves. ServiceNow told The Register it's aware of the blog post and is investigating, while prioritizing protection of customers, their data, and its systems. The episode echoes a March incident when ShinyHunters claimed to have stolen data from around 100 high-profile companies and nearly 400 websites after targeting over-permissioned Experience Cloud guest accounts, though Reco says City-Forum isn't doing quite the same thing. Organizations using these platforms now face the uncomfortable task of auditing what their guest accounts have been showing the world. The lesson is blunt: configuration choices that seemed harmless may have been broadcasting sensitive information to anyone who bothered to ask, and at least one sophisticated actor has been asking for more than a year. For enterprises that assumed their portals were secure by default, the prolonged, high-volume nature of this campaign suggests that assumption was expensive.

