{"slug": "salesforce-servicenow-data-targeted-in-city-forum-attacks", "title": "Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks", "summary": "Researchers at Reco have identified a new attack campaign dubbed 'City-Forum' targeting Salesforce and ServiceNow systems, exposing user data. The attacks, which bear similarities to those by the extortion group ShinyHunters, penetrated systems through the UI-API layer and used a custom toolset to target a native ServiceNow Service Portal search endpoint. Reco warns that organizations should be cautious about granting login credentials.", "body_md": "Records held in [Salesforce and ServiceNow systems are under attack](https://www.reco.ai/blog/city-forum-campaign-salesforce-servicenow) leaving user data exposed, according to researchers at Reco.\n\nThe attack appears similar to those perpetrated by the extortion group ShinyHunters, Reco said. ShinyHunters has been particularly active this year, [attacking dating sites in January](https://www.csoonline.com/article/4124684/shinyhunters-ramp-up-new-vishing-campaign-with-100s-in-crosshairs.html) and [Oracle in June](https://www.csoonline.com/article/4184408/oracle-peoplesoft-zero%E2%80%91day-fuels-shinyhunters-extortion-spree.html), and there are fears that they could have found a new target.\n\nReco has named the latest campaign of attacks “City-Forum,” after a domain name associated with the attackers’ IP address. While it bears similarities to Shiny Hunters’ past exploits, there are also differences. This time around the attacker penetrated the systems through the UI-API layer, an attack point that Reco had not seen used before, and had also created its own toolset to carry out the attack. It is also targeting a native ServiceNow Service Portal search endpoint that has almost no online documentation or well-known open-source tools.\n\nThe threat is particularly noteworthy, Reco said, as the attackers have studied the services to map different common data-leak vectors, a sign of an advanced approach.\n\nRegardless of who the attackers were and how the attack was carried out, one thing should be clear: Organizations should be increasingly careful about who they give login credentials to.\n\n*This article first appeared on CSO.*", "url": "https://wpnews.pro/news/salesforce-servicenow-data-targeted-in-city-forum-attacks", "canonical_source": "https://www.cio.com/article/4209818/salesforce-servicenow-data-targeted-in-city-forum-attacks-2.html", "published_at": "2026-08-14 13:36:41+00:00", "updated_at": "2026-08-14 13:37:43.300502+00:00", "lang": "en", "topics": ["ai-ethics"], "entities": ["Salesforce", "ServiceNow", "Reco", "ShinyHunters"], "alternates": {"html": "https://wpnews.pro/news/salesforce-servicenow-data-targeted-in-city-forum-attacks", "markdown": "https://wpnews.pro/news/salesforce-servicenow-data-targeted-in-city-forum-attacks.md", "text": "https://wpnews.pro/news/salesforce-servicenow-data-targeted-in-city-forum-attacks.txt", "jsonld": "https://wpnews.pro/news/salesforce-servicenow-data-targeted-in-city-forum-attacks.jsonld"}}