Data Theft Campaign Exploits Guest Access in Salesforce and ServiceNow Portals

www.news4hackers.com-data-theft-campaign-exploits-guest-access-in-salesforce-and-servicenow-portals-data-theft-campaign-exploits-guest-access-in-salesforce-and-servicenow-portals

An ongoing City-Forum campaign is targeting information exposed to unauthenticated users through Salesforce Experience Cloud and ServiceNow customer portals, impacting organizations across multiple sectors including telecommunications, banking, financial services, enterprise software, security, data privacy, and the public sector.

Overview of the Campaign

The activity has been linked to IP address 158.220.87.79, hosted by German VPS provider Contabo. The same infrastructure is associated with the city-forum.com domain, which has resolved to the server since at least March 2025. Technical fingerprints matching this infrastructure have been observed in attacks against both Salesforce and ServiceNow environments globally.

Technical Details and Attack Vectors

Targeted Platforms

The attacks do not exploit vulnerabilities in the platforms themselves but instead target data unintentionally made accessible to guest users through overly lenient sharing rules, permissions, or portal configurations. Guest accounts, designed for unauthenticated visitors, provide access to public APIs that can retrieve internal records if permissions are improperly configured.

Attack Methods

Much of the Salesforce activity has focused on the older Aura framework, with attackers probing publicly accessible objects such as Accounts, Contacts, and Cases to identify exposed records. One environment recorded over 560,000 requests targeting these objects. The campaign has also targeted Salesforce sites using the newer Lightning Web Runtime framework, where attackers leverage Salesforce’s UI API and GraphQL requests to extract data accessible to guest accounts.

Additional efforts have focused on Experience Cloud self-registration functions, potentially identifying opportunities for guest users to create authenticated external accounts with expanded access. Similar guest-user exploitation has been seen in previous ShinyHunters data theft campaigns, though no direct connection to City-Forum has been established.

ServiceNow Targeting

ServiceNow Service Portals are being targeted through their native search functionality, which allows anonymous requests to return information when guest access is enabled. Attackers use varying search terms to enumerate exposed data, with one environment experiencing a spike from dozens to hundreds of daily requests. Defenders may detect automated search patterns and volume changes, but ServiceNow transaction logs do not capture POST body content, complicating analysis of specific search terms.

Mitigation Strategies

Administrators are advised to review guest-user sharing rules, object and field permissions, file access settings, member visibility configurations, and self-registration parameters. For Lightning Web Runtime sites, disabling unnecessary guest access to public APIs can mitigate risks associated with data enumeration and exfiltration.

Conclusion

Organizations using Salesforce Experience Cloud or ServiceNow customer portals must prioritize securing guest-user access configurations to prevent data exposure. Proactive monitoring of access patterns and strict enforcement of permissions are critical to mitigating risks from campaigns like City-Forum.

According to the analysis, the campaign highlights the importance of reviewing portal configurations and API access controls to prevent unauthorized data access.



About Author

en_USEnglish