Aug 13, 2026
Policy

City-Forum targets Salesforce and ServiceNow guest access

Reco says an unidentified operator is querying publicly exposed Salesforce and ServiceNow portals, putting customer permission settings under scrutiny.

Dominic Okoye

By Dominic Okoye · Staff Writer

· 3 min read

City-Forum targets Salesforce and ServiceNow guest access
Photo: The Register

City-Forum Salesforce ServiceNow activity is targeting public customer portals through anonymous access, according to Reco, which says an unidentified operator is using custom tools to query data that organizations configured as readable by guest users. The campaign is ongoing, Reco said, and matters because it is described as a customer-permissions problem rather than a confirmed compromise of either vendor’s platform.

Reco named the operation City-Forum after a domain tied to the infrastructure. The domain and associated IP address have been in place since at least March 2025, but the researchers have not established when scanning began. They also have not named targets, identified the actor, or determined what records were retrieved from particular organizations.

The reported targets include telecom companies, banks and other financial-services firms, enterprise software and cybersecurity vendors, and public-sector bodies. Reco said customer logs indicated activity across North America, Europe and Asia, with the Salesforce activity appearing broader than the ServiceNow portion.

Was City-Forum exploiting a Salesforce or ServiceNow vulnerability?

No platform vulnerability or vendor-environment compromise has been alleged in the reporting. Reco said the activity it observed was unauthenticated and retrieved information exposed through customer-controlled permissions, sharing rules, search sources or related settings. In practical terms, a record visible to a portal’s guest user may be visible to an internet visitor.

ServiceNow said it was aware of the third-party report, noted that it did not allege a compromise of the ServiceNow environment, and said it was investigating. Salesforce had not responded to The Register’s questions at the time of that report.

Custom tooling across three access paths

Reco said the operator combined several techniques in one toolset: enumeration of Salesforce’s Aura framework, requests against the UI API GraphQL layer used by Salesforce Lightning Web Runtime sites, and queries to a native ServiceNow Service Portal search endpoint. The researchers said the latter two surfaces have received little public attention compared with existing tools aimed at Aura.

The heaviest identified activity was still on Salesforce Aura. One Salesforce target recorded more than 560,000 events from the tracked IP during the campaign window, Reco said, with almost all of them attempts to enumerate information accessible to guest users. The operator also checked whether Salesforce sites allowed self-registration, which could potentially create a route from anonymous access to an authenticated external account with wider permissions. Reco said it had observed guest-user activity, not authenticated access.

The operation resembles earlier abuse of overly permissive Salesforce guest accounts, including activity associated in reporting with ShinyHunters, but Reco said it could not attribute City-Forum and was not ruling any party in or out. Its distinguishing claim is the custom, cross-platform toolset.

What should portal operators check?

Security teams should review guest and anonymous-user permissions, Salesforce guest sharing rules, self-registration settings, and content available through public ServiceNow search sources. This is the configuration-review work that belongs in an enterprise security program, rather than a vendor patch cycle.

Reco said Salesforce Event Monitoring and ServiceNow transaction logs can help identify requests and searches, but those records may not reveal the precise fields, records or search terms returned. Confirming exposure may require reproducing anonymous requests internally and examining the responses. Reco said it has published indicators of compromise and log-hunting guidance.

This story draws on original reporting from The Register.

More from Policy

All Policy →