A sophisticated threat actor collective operating under the designation "City-Forum" has maintained a sustained data theft campaign targeting Salesforce and ServiceNow instances since at least March 2025. Security researchers tracking the operation report that attackers deployed custom tooling to compromise customer relationship management and IT service management platforms across financial services, healthcare, technology, and manufacturing sectors.
The campaign exploits legitimate access credentials and misconfigurations in cloud-based environments to establish persistence within target networks. Attackers leveraged these footholds to extract sensitive business data, customer information, and proprietary configurations stored within Salesforce and ServiceNow deployments. The use of custom tools indicates the threat actors invested significant resources in developing infrastructure tailored specifically to these platforms.
Salesforce and ServiceNow rank among the most widely deployed enterprise cloud applications globally. Salesforce manages customer interactions and sales pipelines for over 300,000 organizations. ServiceNow administers IT operations, change management, and incident response workflows across similar-scale customer bases. Both platforms function as centralized repositories for sensitive organizational data. Compromise of these systems exposes customer records, financial information, internal processes, and potentially third-party partner details.
City-Forum's operational tempo and targeting patterns suggest a financially motivated threat collective focused on data monetization rather than espionage objectives. The multi-sector approach indicates attackers sell stolen datasets across dark web marketplaces or leverage information for extortion campaigns. Organizations in regulated industries face compounded risk. Healthcare entities risk HIPAA violations if patient data transits through compromised instances. Financial institutions face regulatory fines and reputational damage. Technology companies lose competitive advantage when stolen product roadmaps or customer lists surface.
The campaign's longevity through mid-2025 demonstrates defenders failed to detect and eradicate City-Forum infrastructure rapidly. This suggests attackers either maintained multiple persistence mechanisms or exploited gaps in detection capabilities across targeted organizations. The reliance on credential compromise rather than zero-day exploitation means defenders possess available defensive tools. Organizations cannot blame unknown vulnerabilities for this breach.
Mitigation requires immediate action across multiple vectors. Organizations must audit Salesforce and ServiceNow administrative accounts for unauthorized modifications or suspicious access patterns. Credential rotation targeting high-privilege service accounts prevents attackers from maintaining access through stolen credentials. Multi-factor authentication enforcement blocks authentication abuse even when passwords remain compromised. Organizations should review data export logs within both platforms to identify what information attackers extracted.
Third-party risk assessments become necessary. Organizations must question whether their Salesforce and ServiceNow implementations operated with default configurations or vendor-recommended security hardening. Cloud access security brokers provide additional visibility into lateral movement and data exfiltration attempts. Network segmentation limits the blast radius if attackers penetrate external-facing cloud applications.
City-Forum's sustained operation through mid-2025 reflects broader failures in cloud security maturity. Many organizations treat Salesforce and ServiceNow deployments as managed services with minimal internal security oversight. This assumption proves dangerous. These platforms house data equivalent to internal databases and require equivalent security controls. The campaign underscores that cloud adoption does not transfer security responsibility to vendors. Organizations remain accountable for access controls, monitoring, and incident response within their cloud environments.
