A wave of targeted data-theft attacks is hitting businesses that use Salesforce and ServiceNow — two of the most widely adopted business platforms on the planet. The campaign, which researchers have linked to a threat actor operating under the name "City-Forum," exploits misconfigured customer portals to extract sensitive records without ever needing to crack a single password. If your business relies on either platform, this is worth your full attention.
What the City-Forum Attacks Actually Do
Rather than breaking in through brute force, the City-Forum attackers are taking advantage of portals that have been set up incorrectly. Many Salesforce Experience Cloud sites and ServiceNow customer-facing portals are configured to allow guest access for convenience — so customers can log tickets or check case statuses without creating an account. When access controls are not properly locked down, that guest access can expose far more than intended: internal records, customer data, case notes, and personally identifiable information.
The attackers are systematically probing these portals, identifying the ones with weak or missing access restrictions, and pulling data at scale. No malware, no phishing, no dramatic hack — just automated requests to a door someone left unlocked. This kind of attack is quiet, fast, and hard to detect if you are not actively monitoring what is leaving your systems.
Why Small and Mid-Sized Businesses Are at Higher Risk
Large enterprises typically have dedicated security teams reviewing platform configurations on a regular cycle. SMBs usually do not. A Salesforce portal might have been set up two years ago by a consultant who has since moved on. A ServiceNow instance might be running with default settings that felt fine at the time. Nobody has gone back to check.
This is exactly the gap that campaigns like City-Forum are designed to exploit. Attackers are not necessarily targeting your business by name — they are running automated scans across the internet looking for misconfigured portals, and they will find yours if it is exposed. The stolen data then ends up packaged and sold on dark web markets, where it can be used for follow-on attacks, fraud, or identity theft against your customers and staff.
The downstream consequences are serious. A data breach — even one caused by a configuration error rather than a sophisticated intrusion — can trigger regulatory obligations, damage customer trust, and in some jurisdictions carry significant financial penalties.
How Stolen Data Gets Used After the Breach
Once data is extracted through portal abuse, it typically moves through a predictable chain. It gets compiled into dumps, traded between threat actors, and eventually surfaces in infostealer logs, breach databases, and credential marketplaces on the dark web. By the time your customers start reporting suspicious activity, the data may have been circulating for weeks or months.
This lag is one of the biggest challenges in breach response. The initial extraction event is often invisible. What becomes visible later — fraudulent logins, account takeovers, phishing emails that reference real account details — is the downstream damage. For businesses that have not been monitoring their exposure, this is when they first realise something went wrong.
That is why monitoring across breach databases, infostealer dumps, dark web markets, and public sources is not a luxury reserved for large companies. It is the early warning system that gives you time to act before the damage compounds.
What You Should Do Right Now
Start by auditing the access controls on any customer-facing portals you operate, particularly if you use Salesforce Experience Cloud or ServiceNow. If you are not sure how they are configured, ask your administrator or implementation partner to review guest access permissions specifically. Many misconfigurations come down to a single setting that nobody thought to revisit.
Beyond your own platforms, consider what data about your business and your customers is already out there. Credentials harvested from previous breaches, employee email addresses in phishing lists, and corporate data sitting in public code repositories all represent live exposure that attackers can use to get a foothold — even if your portals are correctly configured today.
In an environment where Salesforce and ServiceNow data theft is being carried out at scale, knowing your exposure is the first and most actionable step you can take. Run a free audit at breachrr.com/audit to see what we find across breach records, dark web sources, and your domain infrastructure — before someone else finds it first.
Want to see if your company is exposed?