City-Forum Campaign Has Targeted Salesforce and ServiceNow Users Since 2025

A data-theft operation known as the “City-Forum” campaign has been active since at least March 2025, according to available reporting. The campaign has focused on organizations in multiple sectors and...

A data-theft operation known as the “City-Forum” campaign has been active since at least March 2025, according to available reporting. The campaign has focused on organizations in multiple sectors and has used custom-built tooling, indicating an effort tailored to the environments or services used by each target.

The activity has been linked to targets using Salesforce and ServiceNow, two widely deployed enterprise platforms. Salesforce is commonly used for customer relationship management and related business workflows, while ServiceNow supports IT service management and other operational processes. Access to either platform could expose sensitive business records, although the available information does not establish what data was taken from individual victims.

Limited public detail

Information currently available about City-Forum is limited. The campaign’s operators, initial access methods, specific victims and the scale of any theft have not been identified in the supplied reporting. There is also no confirmed indication that the platforms themselves were compromised. References to Salesforce and ServiceNow may instead describe organizations or accounts targeted through their use of those services.

The reported use of custom tooling is significant because purpose-built components can help attackers adapt their activity to different environments and reduce reliance on publicly documented tools. However, the available account does not provide technical details that would clarify how the tooling operates or how it is delivered.

Organizations using cloud business platforms should continue to review authentication events, monitor unusual access to sensitive records and apply strong identity protections, including multifactor authentication where available. Security teams should also investigate unexpected administrative activity and review integrations or access tokens that are no longer required. These measures are general precautions and are not tied to a confirmed City-Forum technique.

Further reporting will be needed to determine the campaign’s operators, victims, tactics and overall impact.