By Interestana AI Editorial — AI-drafted, human-overseen. How we report
One Attacker Scraped Salesforce, ServiceNow Portals Since 2025

A single attacker has been exfiltrating data from customer portals belonging to Salesforce and ServiceNow across various industries for over a year, as detailed in research published this week by Reco, an agent security platform. This ongoing campaign, which Reco has dubbed the City Forum campaign, is linked to a specific IP address and domain associated with the threat actor. The research traces the extensive data theft back to a single server, identified as 158.220.87.79, which is hosted on a cloud infrastructure provider. This persistent activity highlights a significant security vulnerability affecting businesses that utilize these widely adopted customer relationship management (CRM) and IT service management (ITSM) platforms.
The City Forum campaign's operational timeline began in 2025 and has continued uninterrupted, demonstrating a sophisticated and sustained effort by the attacker to gain unauthorized access to sensitive customer information. The research indicates that the attacker has been systematically scraping records from these portals, suggesting a targeted approach to data acquisition. While the exact nature and volume of the data stolen have not been fully disclosed, the implication of scraping customer portals points to the potential compromise of customer lists, contact information, and possibly other business-critical data stored within these systems. The use of a single, dedicated server for these operations suggests a controlled and deliberate infrastructure setup by the attacker.
Reco's analysis identified the campaign by observing unusual network traffic patterns and unauthorized data access attempts originating from the identified server. The campaign's name, City Forum, is derived from a domain that was found to be connected to the attacker's infrastructure, serving as a key indicator for the researchers. The persistence of this campaign for more than a year underscores the challenges in detecting and mitigating such advanced threats, especially when they leverage legitimate-looking infrastructure. The findings serve as a critical alert for organizations relying on Salesforce and ServiceNow, emphasizing the need for enhanced security monitoring and data protection measures.
Salesforce and ServiceNow are leading providers of cloud-based software for customer relationship management and IT service management, respectively. Their platforms are used by millions of businesses globally to manage customer interactions, sales processes, and IT operations. The compromise of these platforms can have far-reaching consequences, impacting not only the direct customers of Salesforce and ServiceNow but also the end-customers whose data is managed within these systems. The City Forum campaign's success in operating undetected for an extended period suggests potential gaps in the security protocols of the affected organizations or a sophisticated evasion technique employed by the attacker. Reco's research aims to bring attention to this threat and encourage proactive security enhancements within the ecosystem of these critical business platforms.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.