Researchers report an ongoing cybercrime campaign dubbed “City-Forum” that targets Salesforce and ServiceNow. The attackers use a custom toolset to identify, quietly collect, and exfiltrate data exposed through the platforms’ publicly reachable portals.

According to the reports, the intrusion relies on unauthenticated or anonymous “guest” access, allowing the attackers to enumerate available information without logging in. In both outlets’ descriptions, the compromised entry points are Salesforce Experience Cloud and ServiceNow customer portals, where misconfiguration or exposed functionality can make data accessible to non-authenticated users.

The coverage is aligned on the core technical theme: the attackers exploit anonymous access paths to discover and retrieve data at scale while attempting to avoid detection. Differences are mainly in framing and wording rather than substance, including references to the campaign’s stealth and the specific mechanisms by which data is enumerated and stolen.