Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2493+ Articles
160+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025
NEWS

One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025

Dubbed 'City Forum,' a single threat actor has been silently scraping customer portals across Salesforce and ServiceNow for over a year.

Dylan H.

News Desk

August 18, 2026
4 min read

"City Forum" Campaign: A Single Threat Actor, Two Major Platforms

A newly published research report from Reco, an agent security platform, has revealed a sustained data scraping campaign targeting both Salesforce and ServiceNow customer portals. Dubbed the "City Forum" campaign, the activity has been traced to a single piece of infrastructure that has been quietly pulling records from enterprise portals across multiple industries for more than a year — beginning in 2025 and continuing into 2026.

The campaign's discovery underscores a growing threat to enterprise SaaS environments: sophisticated, patient attackers who exploit legitimate platform access to exfiltrate data at scale without triggering traditional security alerts.

How the Campaign Works

Unlike ransomware or destructive intrusions, the City Forum campaign relies on low-and-slow data scraping — a technique designed to blend in with normal user behavior. The attacker's infrastructure:

  • Authenticated to customer-facing Salesforce and ServiceNow portals using valid credentials, likely obtained through prior phishing campaigns, credential stuffing, or purchased on dark web markets
  • Systematically queried and extracted customer records, support tickets, contact information, and other data accessible through these portals
  • Operated from consistent infrastructure that allowed Reco researchers to connect the Salesforce and ServiceNow activity to a single threat actor

The cross-platform nature of the campaign is particularly notable — it suggests an attacker with broad access to compromised enterprise SaaS accounts, the technical sophistication to automate portal scraping, and the patience to sustain an operation over many months.

Industries Targeted

According to the Reco report, the City Forum campaign has affected organizations across multiple industries, though specific victim organizations have not been named. The use of Salesforce (CRM) and ServiceNow (IT service management) portals as targets suggests the attacker is particularly interested in:

  • Customer contact details and relationship data
  • IT support tickets containing sensitive system information
  • Business process data that could be used for targeted social engineering

Why This Is Hard to Detect

Data scraping campaigns that use legitimate credentials present a significant detection challenge:

  • No malware is deployed — the attacker uses standard portal interfaces
  • Activity mimics legitimate user behavior — regular queries at normal speeds
  • Alerts are rarely triggered — most DLP and SIEM rules focus on bulk downloads, not sustained low-volume queries
  • Shared infrastructure is hard to attribute — connecting activity across two different SaaS platforms required advanced behavioral analysis

This is precisely why security teams are increasingly investing in User and Entity Behavior Analytics (UEBA) and AI-driven anomaly detection that can identify subtle deviations from baseline behavior over extended periods.

What Organizations Should Do

Organizations using Salesforce, ServiceNow, or similar enterprise SaaS platforms should take the following steps to reduce exposure:

  1. Audit portal access logs for sustained, systematic query patterns from the same user accounts or IP ranges
  2. Enable MFA on all portal accounts — especially customer-facing or partner-facing portals
  3. Apply least-privilege access — limit which portal users can access bulk record queries
  4. Monitor for credential compromise using threat intelligence feeds and dark web monitoring services
  5. Review third-party integrations that may have broad data access permissions on your SaaS platforms
  6. Deploy behavioral analytics capable of detecting slow, sustained data access anomalies

The Bigger Picture: SaaS as an Attack Surface

The City Forum campaign illustrates that attackers have adapted to the enterprise shift toward SaaS. Rather than targeting on-premises systems, sophisticated threat actors now focus on the vast repositories of sensitive data accessible through legitimate SaaS portals — often with minimal friction once valid credentials are obtained.

As enterprises consolidate more business-critical data in platforms like Salesforce and ServiceNow, the value of persistent, authenticated access to these portals continues to grow — making them prime targets for patient, intelligence-focused threat actors.

Sources

  • The Hacker News — City Forum Campaign Coverage
  • Reco — Agent Security Platform Research
#Threat Intelligence#Salesforce#ServiceNow#Data Scraping#SaaS Security

Related Articles

"City-Forum" Data-Theft Attacks Target Salesforce and ServiceNow Portals

A 17-month stealth campaign uses custom Go tooling to scrape enterprise data from misconfigured Salesforce and ServiceNow guest-user portals.

4 min read

Microsoft Maps Three Salesforce Attack Paths Tied to a Year of ShinyHunters Activity

Microsoft has detailed three distinct attack paths used by actors aligned with ShinyHunters to infiltrate corporate Salesforce environments over the past...

6 min read

Scope of Salesforce Attacks Expands as Icarus Leaks Stolen Data

More victims have surfaced after attackers breached application vendor Klue and abused its OAuth tokens to access customers' Salesforce environments. The...

4 min read
Back to all News