Back to News
Cybersecurity

Ongoing Data Theft Campaign Exploiting Salesforce and ServiceNow Vulnerabilities

The City-Forum campaign highlights persistent cybersecurity threats targeting major platforms like Salesforce and ServiceNow.

The City-Forum campaign has been identified as a long-running data theft initiative that has been active since at least March 2025, targeting organizations across various sectors. Utilizing custom tooling, the attackers have successfully infiltrated systems leveraging vulnerabilities within well-known platforms such as Salesforce and ServiceNow. This campaign underscores the evolving nature of cyber threats, as attackers continually develop sophisticated methods to exploit popular enterprise solutions.

For businesses, this serves as a critical reminder of the importance of robust cybersecurity measures, especially for organizations that rely on these platforms for their operations. Implementing advanced security protocols, including regular vulnerability assessments and employee training on phishing and social engineering tactics, is essential to mitigate risks. The implications of this campaign are significant; not only does it threaten sensitive data, but it also poses a risk to the integrity of operational processes within organizations. As cybercriminals increasingly target high-profile platforms, understanding the landscape and bolstering defenses becomes paramount for safeguarding corporate assets in an AI-driven world.

---

*Originally reported by [Dark Reading](https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow)*