"City Forum" Campaign: A Single Threat Actor, Two Major Platforms
A newly published research report from Reco, an agent security platform, has revealed a sustained data scraping campaign targeting both Salesforce and ServiceNow customer portals. Dubbed the "City Forum" campaign, the activity has been traced to a single piece of infrastructure that has been quietly pulling records from enterprise portals across multiple industries for more than a year — beginning in 2025 and continuing into 2026.
The campaign's discovery underscores a growing threat to enterprise SaaS environments: sophisticated, patient attackers who exploit legitimate platform access to exfiltrate data at scale without triggering traditional security alerts.
How the Campaign Works
Unlike ransomware or destructive intrusions, the City Forum campaign relies on low-and-slow data scraping — a technique designed to blend in with normal user behavior. The attacker's infrastructure:
- Authenticated to customer-facing Salesforce and ServiceNow portals using valid credentials, likely obtained through prior phishing campaigns, credential stuffing, or purchased on dark web markets
- Systematically queried and extracted customer records, support tickets, contact information, and other data accessible through these portals
- Operated from consistent infrastructure that allowed Reco researchers to connect the Salesforce and ServiceNow activity to a single threat actor
The cross-platform nature of the campaign is particularly notable — it suggests an attacker with broad access to compromised enterprise SaaS accounts, the technical sophistication to automate portal scraping, and the patience to sustain an operation over many months.
Industries Targeted
According to the Reco report, the City Forum campaign has affected organizations across multiple industries, though specific victim organizations have not been named. The use of Salesforce (CRM) and ServiceNow (IT service management) portals as targets suggests the attacker is particularly interested in:
- Customer contact details and relationship data
- IT support tickets containing sensitive system information
- Business process data that could be used for targeted social engineering
Why This Is Hard to Detect
Data scraping campaigns that use legitimate credentials present a significant detection challenge:
- No malware is deployed — the attacker uses standard portal interfaces
- Activity mimics legitimate user behavior — regular queries at normal speeds
- Alerts are rarely triggered — most DLP and SIEM rules focus on bulk downloads, not sustained low-volume queries
- Shared infrastructure is hard to attribute — connecting activity across two different SaaS platforms required advanced behavioral analysis
This is precisely why security teams are increasingly investing in User and Entity Behavior Analytics (UEBA) and AI-driven anomaly detection that can identify subtle deviations from baseline behavior over extended periods.
What Organizations Should Do
Organizations using Salesforce, ServiceNow, or similar enterprise SaaS platforms should take the following steps to reduce exposure:
- Audit portal access logs for sustained, systematic query patterns from the same user accounts or IP ranges
- Enable MFA on all portal accounts — especially customer-facing or partner-facing portals
- Apply least-privilege access — limit which portal users can access bulk record queries
- Monitor for credential compromise using threat intelligence feeds and dark web monitoring services
- Review third-party integrations that may have broad data access permissions on your SaaS platforms
- Deploy behavioral analytics capable of detecting slow, sustained data access anomalies
The Bigger Picture: SaaS as an Attack Surface
The City Forum campaign illustrates that attackers have adapted to the enterprise shift toward SaaS. Rather than targeting on-premises systems, sophisticated threat actors now focus on the vast repositories of sensitive data accessible through legitimate SaaS portals — often with minimal friction once valid credentials are obtained.
As enterprises consolidate more business-critical data in platforms like Salesforce and ServiceNow, the value of persistent, authenticated access to these portals continues to grow — making them prime targets for patient, intelligence-focused threat actors.