Particle.news
Download on the App Store

City-Forum Campaign Steals Data From Salesforce and ServiceNow Guest Accounts

Researchers warn a single long-running German host uses protocol-legitimate requests to harvest records that organizations exposed to unauthenticated guest users.

Overview

  • Reco published its findings on Wednesday, August 12, 2026, saying the campaign is active and climbing in volume and that the same infrastructure has run since at least March 2025.
  • All attacks trace to one Contabo-hosted IP (158.220.87.79) resolving to city-forum.com and use a custom Go binary that targets Salesforce Aura, the newer LWR GraphQL UI API, and ServiceNow portal search endpoints.
  • The attacker abuses misconfigured Guest User access rather than platform flaws so any record, file, or search source left readable to anonymous users can be enumerated and downloaded.
  • Exfiltration is high-volume but protocol-legitimate, which produced large event counts on victims yet left few obvious anomalies in logs and made it hard to see exact ServiceNow search terms.
  • Reco published IOCs and clear fixes for defenders, including auditing guest sharing rules and permissions, disabling unnecessary guest API access for LWR, turning off self-registration if not needed, and restricting ServiceNow search sources to authenticated contexts.