New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide
Brief
A newly identified threat actor is running a large-scale, long-running cyber campaign targeting Salesforce Experience Cloud sites and ServiceNow Service Portals globally.
Dubbed the “City-Forum Campaign” after a domain tied to the attacker’s infrastructure, the operation has been quietly siphoning data from telecommunications providers, banks, financial services firms, enterprise software vendors, and public-sector portals since at least March 2025.
Unlike known cybercrime groups such as ShinyHunters, which typically abuse Salesforce’s legacy Aura framework via over-permissioned guest user accounts, this threat actor has engineered a more advanced approach.
While the campaign continues to leverage high-volume Aura enumeration, it also targets Salesforce’s newer Lightning Web Runtime (LWR) sites through UI-API a data layer lacking public exploitation tooling or documented research.
