Hackers Used Guest Access to Quietly Steal Data From Salesforce and ServiceNow

A newly spotted campaign, tracked as 'City-Forum', used anonymous login features built into two widely used business platforms to map and copy out sensitive data, no stolen password required.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A hacker's workstation with multiple browser windows and database query tools open, showing corporate data being copied and transferred, dim lighting and focus
Share

Key points

  • Researchers uncovered a novel campaign, tracked as 'City-Forum', targeting Salesforce and ServiceNow.
  • Attackers exploited unauthenticated guest access, needing no username or password to begin.
  • A custom toolset quietly mapped exposed data and copied it without triggering obvious alarms.
  • Attribution remains unclear; no nation-state cluster has been formally linked to the campaign.

What actually happened?

Hackers found a quiet way in: the guest login feature both platforms offer by default. Salesforce and ServiceNow are cloud software tools used by hundreds of thousands of organisations to manage customers and internal workflows. Both allow limited anonymous access so outsiders can submit a support request without creating an account.

The City-Forum campaign, first detailed by SecurityWeek, turned that convenience into an attack path. Using a purpose-built toolkit, the hackers probed each platform's publicly reachable areas, worked out what data was visible to an unauthenticated user, and copied it out. No phishing email was needed, where criminals send fake messages to trick staff into handing over passwords. Just a feature that was already switched on.

Salesforce data exposures have form. We covered ShinyHunters threatening to release 4.9 million Brinks Home Salesforce records on 30 July, a reminder that the platform holds data valuable enough to extort over.

Why is this harder to spot than a normal breach?

The traffic looked normal. Guest logins happen every day on both platforms, so automated security tools watching for suspicious sign-ins would've seen nothing unusual early on.

That's the operationally interesting part. Enumerating exposed records, meaning systematically listing what data is accessible, through a legitimate access path is a low-noise approach that sits below many detection thresholds. The attackers' custom toolset appears designed to stay within that quiet zone.

At medium confidence, the campaign looks financially or espionage-motivated rather than opportunistic, given the precision of the tooling. No overlapping infrastructure with known nation-state clusters has been publicly reported. Single-source attribution calls are premature here.

Should your organisation be worried?

If you run Salesforce or ServiceNow and haven't audited what guest users can see, check now. The attack works only when guest access is enabled and data isn't properly gated behind a login requirement.

For people whose details sit inside a company's Salesforce or ServiceNow instance, the concern is that information could've been copied without the company knowing. Watch for unexpected contact from people who seem to know details about your account or recent support requests.

Platform Access method abused Tool type used Attribution status
Salesforce Unauthenticated guest access Custom toolset Unknown
ServiceNow Unauthenticated guest access Custom toolset Unknown

A feature doesn't have to be broken to be dangerous. Guest access left open on a platform holding sensitive records is enough of a gap for a patient, well-equipped attacker to work with.

© 2026 Threat Vectr