HackMyIP
← Back to News
2026-08-12 Dark Reading

City-Forum APT Campaign Steals Salesforce and ServiceNow Data Since March 2025

APTData BreachThreat Intel

A long-running cyber-espionage operation dubbed "City-Forum" has been systematically exfiltrating sensitive data from enterprise Salesforce and ServiceNow instances since at least March 2025, according to researchers tracking the campaign. The threat actors behind the operation have deployed custom-built tooling designed to blend into normal platform activity, making detection particularly difficult for blue teams operating without specialized cloud monitoring.

The campaign has struck organizations across multiple verticals, including technology, financial services, and government-adjacent sectors. Attackers leverage legitimate API access tokens and session credentials—often harvested through prior phishing or infostealer infections—to pivot through Salesforce CRM environments and ServiceNow workflow portals. Once inside, the custom City-Forum tooling automates large-scale record extraction, focusing on customer contact databases, internal case notes, and configuration tables containing privileged integration credentials. Security teams can proactively audit their own exposure using a email breach checker to determine whether employee credentials have appeared in known stealer logs that could fuel this kind of campaign.

Unlike opportunistic cybercrime groups, City-Forum demonstrates hallmarks of a state-sponsored APT: methodical target selection, patient dwell times measured in weeks rather than hours, and infrastructure designed for persistence rather than quick monetization. Researchers note that the group's command-and-control nodes are fronted by compromised business VPNs and residential proxy pools, complicating attribution. Defenders investigating potential compromise should run a DNS leak test on egress points and a WHOIS lookup on suspicious outbound domains to identify overlapping infrastructure.

Mitigation requires tightening OAuth scopes on connected apps, enforcing IP allowlisting for administrative roles, and reviewing ServiceNow MID Server configurations for unauthorized instances. Organizations should also audit Salesforce Event Monitoring logs for anomalous SOQL queries and bulk export operations predating March 2025, as early-stage reconnaissance may already have occurred. Given the campaign's emphasis on stealth over speed, continuous threat-intel ingestion and token-rotation hygiene remain the most effective defensive postures.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →