Hackers Used Guest Access to Quietly Steal Data From Salesforce and ServiceNow

A newly spotted campaign, tracked as 'City-Forum', used anonymous login features built into two widely used business platforms to map and copy out sensitive data, no stolen password required.

ThreatVectr Newsdesk· 3 min read
Aerial 16:9 view looking straight down at a large outdoor stadium at dusk, floodlights illuminating the pitch, surrounding city lights fading into the distance,
Share

Key points

  • Researchers uncovered a novel campaign, tracked as 'City-Forum', targeting Salesforce and ServiceNow, two of the most widely used business software platforms in the world.
  • Attackers exploited unauthenticated guest access, meaning they needed no username or password to get started.
  • A custom toolset was used to quietly map out exposed data and copy it without triggering obvious alarms.
  • Attribution remains unclear at this stage; no nation-state cluster has been formally linked to the campaign.

What actually happened?

Hackers found a quiet way in: the guest login feature that both platforms offer by default. Salesforce and ServiceNow are cloud software tools that hundreds of thousands of organisations use to manage customers, IT support tickets, and internal workflows. Both allow limited anonymous access so that outsiders can, for instance, submit a support request without creating an account.

The City-Forum campaign, first detailed by SecurityWeek, turned that convenience into an attack path. Using a purpose-built toolkit, the hackers probed each platform's publicly reachable areas, worked out what data was visible to an unauthenticated user, and then quietly copied it out. No phishing email, where criminals send fake messages to trick staff into handing over passwords, was needed. No stolen credential. Just a feature that was already switched on.

Why is this harder to spot than a normal breach?

Because the traffic looked normal. Guest logins happen every day on both platforms, so automated security tools watching for suspicious sign-ins would have seen nothing unusual in the early stages.

This is the part that makes the City-Forum technique operationally interesting from a threat-intelligence standpoint. Enumerating exposed records, meaning systematically listing what data is accessible, through a legitimate access path is a low-noise approach that sits below many detection thresholds. The attackers' custom toolset appears designed specifically to stay within that quiet zone.

At medium confidence, the campaign looks financially or espionage-motivated rather than opportunistic, given the precision of the tooling. No overlapping infrastructure with known nation-state clusters, such as Sandworm (tracked by Mandiant) or Mustang Panda (tracked by Recorded Future), has been publicly reported. Single-source attribution calls are premature here.

Should your organisation be worried?

If you run Salesforce or ServiceNow and have not audited what guest users can see, yes, you should check. The attack works only when guest access is enabled and data is not properly gated behind a login requirement.

For ordinary people whose details sit inside a company's Salesforce or ServiceNow instance, such as customer records, support tickets, or HR data, the practical concern is that information could have been copied without the company knowing. Watch for unexpected contact from people who seem to know details about your account or recent support requests. If a company you deal with contacts you about a data exposure, take it seriously.

Platform Access method abused Tool type used Attribution status
Salesforce Unauthenticated guest access Custom toolset Unknown
ServiceNow Unauthenticated guest access Custom toolset Unknown

The core lesson is blunt. A feature does not have to be broken to be dangerous. Guest access left open on a platform holding sensitive records is enough of a gap for a patient, well-equipped attacker to work with.

© 2026 Threat Vectr