Long-Running 'City-Forum' Campaign Targets Salesforce and ServiceNow Data
Security researchers have identified an ongoing data theft campaign, dubbed 'City-Forum,' that has been active since at least March 2025. The campaign uses custom tooling to target organizations across multiple sectors, with a focus on businesses relying on popular cloud platforms such as Salesforce and ServiceNow.
These platforms are widely used by businesses of all sizes to manage customer relationships, sales pipelines, and IT service operations, making them attractive targets for attackers seeking to steal sensitive business and customer data. The long-running nature of this campaign suggests attackers have found sustained value in targeting these systems, potentially exploiting misconfigurations, weak access controls, or compromised credentials to gain entry.
While specific technical details of the campaign's methods remain limited, its persistence and cross-sector targeting highlight the growing risk to organizations that store critical data in cloud-based CRM and IT service platforms. Australian small businesses using these tools should treat this as a reminder to review who has access to their cloud systems and how that access is protected.