"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
A data theft campaign dubbed 'City-Forum' is actively targeting Salesforce Experience Cloud and ServiceNow customer portals, using custom tools to extract data that those platforms expose to anonymous, unauthenticated users.
Why this matters: The twist here is that attackers are not breaking through locked doors. They are walking through ones left open to the public. Salesforce and ServiceNow portals are used by cities, utilities, healthcare systems, and businesses to let customers check cases, submit requests, and track services. If those portals expose records to anyone without logging in, a custom scraping tool can quietly drain them. You may never have heard of either platform, but your data could be sitting in one. The organizations running these portals owe you a tighter configuration, not just a breach notice after the fact.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.