The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

August 12, 2026

An unknown threat actor has been using a custom toolset to probe Salesforce and ServiceNow instances with overly permissive guest access and steal data for more than a year.

The targets have spanned multiple sectors, including telecommunications, financial services, enterprise software, security and data-privacy companies, and public-sector portals worldwide. Researchers at AI cybersecurity firm Reco, who are tracking the campaign, have dubbed it "City-Forum" after the domain name linked to the attacker’s IP address, and it's been active since at least March 2025.

What makes the campaign notable, according to Reco, is the extent to which the threat actor appears to have researched the two platforms and then built their own tools to identify data that organizations may have inadvertently left accessible to guest users.