Threat Intelligence

Long-Running 'City-Forum' Campaign Targets Salesforce and ServiceNow Data

Dark Reading · 13 Aug 2026
Key Takeaway Review and tighten access controls, enable multi-factor authentication, and monitor for unusual activity on your Salesforce, ServiceNow, or other cloud platforms.

Security researchers have identified an ongoing data theft campaign, dubbed 'City-Forum,' that has been active since at least March 2025. The campaign uses custom tooling to target organizations across multiple sectors, with a focus on businesses relying on popular cloud platforms such as Salesforce and ServiceNow.

These platforms are widely used by businesses of all sizes to manage customer relationships, sales pipelines, and IT service operations, making them attractive targets for attackers seeking to steal sensitive business and customer data. The long-running nature of this campaign suggests attackers have found sustained value in targeting these systems, potentially exploiting misconfigurations, weak access controls, or compromised credentials to gain entry.

While specific technical details of the campaign's methods remain limited, its persistence and cross-sector targeting highlight the growing risk to organizations that store critical data in cloud-based CRM and IT service platforms. Australian small businesses using these tools should treat this as a reminder to review who has access to their cloud systems and how that access is protected.

data theft Salesforce ServiceNow cloud security cyber threat

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.