A single attacker has systematically harvested records from Salesforce and ServiceNow customer portals across multiple industries since early 2025, according to research from Reco, an agent security platform.

The campaign, which Reco named City Forum after a domain associated with the attacker's infrastructure, operated from a single IP address: 158.220.87.79. This infrastructure pulled data from both cloud platforms over an extended period, targeting customer portals that store sensitive business information.

Salesforce and ServiceNow both host customer data portals that many enterprises use to manage relationships, support tickets, and service configurations. These portals often contain API keys, authentication tokens, customer lists, and internal communications. An attacker with sustained access to multiple customer instances across both platforms gains exposure to a broad supply of corporate intelligence and credentials.

The campaign's longevity reveals detection gaps in how organizations monitor third-party cloud platforms. Reco's research indicates the attacker leveraged legitimate portal access mechanisms rather than exploiting zero-day vulnerabilities. This suggests the attacker either compromised valid credentials or exploited a configuration weakness that allowed unauthorized scraping without triggering alerts.

The multi-industry scope indicates this was not a targeted campaign. The attacker collected data wherever portals were accessible, suggesting automated reconnaissance and extraction tools. This approach maximizes volume and increases the likelihood of finding high-value targets within the harvest.

Salesforce and ServiceNow did not immediately respond to requests for comment regarding the City Forum campaign. Both companies maintain that customer data isolation prevents one customer's environment from exposing another's information. However, attackers targeting shared infrastructure or exploiting platform-level weaknesses can sometimes access multiple customer instances without compromising the entire platform.

Organizations using Salesforce and ServiceNow should audit portal access logs for suspicious activity dating back to early 2025. Reco recommends checking for unusual API calls, bulk data exports, or access patterns from unfamiliar IP addresses. Any activity originating from or routing through 158.220.87.79 warrants immediate investigation.

The campaign raises questions about monitoring blind spots in cloud adoption. Many organizations assume their cloud provider handles security monitoring, but detecting slow, sustained data exfiltration requires customer-side logging and alert configuration. Default logging settings in Salesforce and ServiceNow often lack the granularity needed to catch scraping campaigns that move data gradually over weeks or months.

Customers should implement multi-factor authentication on all portal accounts, restrict API access to specific IP ranges, and enable detailed audit logging for data access events. Rate limiting on API endpoints can detect automated scraping tools. Regular review of active sessions and API tokens removes orphaned credentials that attackers can repurpose.

The City Forum campaign demonstrates a persistent threat model: attackers don't need zero-days or sophisticated exploits when they can rely on weak credential hygiene and incomplete monitoring. A single infected machine with valid portal credentials becomes a pipeline for continuous data extraction across enterprise platforms.