Security researchers have identified a long-running data theft campaign, tracked as City-Forum, that has been targeting organizations that rely on Salesforce and ServiceNow platforms. The campaign has reportedly been active since at least March 2025, indicating a sustained and well-resourced operation rather than an opportunistic smash-and-grab effort.
According to the reporting, the threat actors behind City-Forum have hit organizations across multiple sectors, suggesting the campaign is not narrowly focused on a single industry vertical. Both Salesforce and ServiceNow are widely used SaaS platforms that store large volumes of sensitive customer, employee, and operational data, making them attractive targets for actors seeking to exfiltrate information at scale.
Custom Tooling Raises the Stakes
Notably, the campaign relies on custom-built tooling rather than off-the-shelf malware or commodity attack frameworks. The use of purpose-built tools for targeting these specific SaaS platforms points to a threat actor with the technical capability and motivation to invest in bespoke infrastructure, rather than relying on generic phishing kits or publicly available exploit code.
The extended duration of the campaign, spanning several months without broad public detection, underscores a persistent challenge for organizations that depend on cloud-based CRM and IT service management platforms: visibility into third-party SaaS environments often lags behind on-premises security monitoring.
What Security Teams Should Do
Organizations using Salesforce or ServiceNow should consider the following steps in light of this campaign:
- Review authentication logs and API access patterns for Salesforce and ServiceNow instances for anomalous activity.
- Audit third-party integrations and connected applications that have access to these platforms.
- Ensure multi-factor authentication is enforced across all administrative and privileged accounts on these SaaS platforms.
- Monitor for unusual data export or bulk query activity that could indicate exfiltration attempts.
Further technical details about the specific tactics, techniques, and indicators of compromise associated with City-Forum have not yet been fully disclosed. Organizations relying on these platforms should stay alert for updated guidance as more information becomes available.
