Persistent 'City-Forum' Campaign Exfiltrates Data from Salesforce and ServiceNow Environments
The 'City-Forum' campaign demonstrates how threat actors are increasingly targeting cloud-based SaaS platforms that house sensitive business data, customer records, and operational information. By deploying custom malware and tailored techniques against widely-used platforms like Salesforce and ServiceNow, attackers can achieve broad organizational impact across multiple industries simultaneously. The campaign's longevity — active since at least March 2025 — suggests that many organizations lacked sufficient monitoring to detect the intrusion in a timely manner. This matters because SaaS platforms often hold an organization's most critical data assets, yet security teams frequently underestimate the need to apply traditional security controls in cloud environments.
Tactical Insight
Immediate actions
- Audit all active API integrations, OAuth tokens, and connected applications within Salesforce and ServiceNow for unauthorized access.
- Enable and review platform-native security event logs (e.g., Salesforce Event Monitoring, ServiceNow Security Incident Response) for anomalous data access or export activity.
- Rotate credentials and revoke unused API keys or service accounts with access to these platforms.
Long-term improvements
- Implement a Cloud Access Security Broker (CASB) to enforce data loss prevention (DLP) policies and detect abnormal SaaS data exfiltration patterns.
- Apply the principle of least privilege across all SaaS user roles, limiting bulk data export permissions to only those with a verified business need.
- Establish a SaaS Security Posture Management (SSPM) program to continuously assess configuration drift and security gaps in cloud platforms.
Detection measures
- Deploy UEBA (User and Entity Behavior Analytics) to baseline normal user activity in Salesforce and ServiceNow and alert on deviations such as mass record downloads.
- Integrate SaaS platform logs into your SIEM and create detection rules specifically for large-volume data exports, after-hours access, and access from unexpected geolocations.
- Conduct regular threat hunts focused on indicators of custom malware persistence within SaaS-connected endpoints and integration layers.