[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fXH-DN2VIpGRws1Noungsr8GU1dOQg0NoGq9eJXNG0KM":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":26,"created_at":27,"published_at":28,"article":29,"tags":33,"podcasts":52},"fa4a1e76-5c79-445f-b81a-919f550a46af","persistent-city-forum-campaign-exfiltrates-data-from-salesforce-and-servicenow-environments","2b70d9b8-dc8a-4ef4-bee8-cc720b33f295","Persistent 'City-Forum' Campaign Exfiltrates Data from Salesforce and ServiceNow Environments","The 'City-Forum' campaign demonstrates how threat actors are increasingly targeting cloud-based SaaS platforms that house sensitive business data, customer records, and operational information. By deploying custom malware and tailored techniques against widely-used platforms like Salesforce and ServiceNow, attackers can achieve broad organizational impact across multiple industries simultaneously. The campaign's longevity — active since at least March 2025 — suggests that many organizations lacked sufficient monitoring to detect the intrusion in a timely manner. This matters because SaaS platforms often hold an organization's most critical data assets, yet security teams frequently underestimate the need to apply traditional security controls in cloud environments.","**Immediate actions:**\n- Audit all active API integrations, OAuth tokens, and connected applications within Salesforce and ServiceNow for unauthorized access.\n- Enable and review platform-native security event logs (e.g., Salesforce Event Monitoring, ServiceNow Security Incident Response) for anomalous data access or export activity.\n- Rotate credentials and revoke unused API keys or service accounts with access to these platforms.\n\n**Long-term improvements:**\n- Implement a Cloud Access Security Broker (CASB) to enforce data loss prevention (DLP) policies and detect abnormal SaaS data exfiltration patterns.\n- Apply the principle of least privilege across all SaaS user roles, limiting bulk data export permissions to only those with a verified business need.\n- Establish a SaaS Security Posture Management (SSPM) program to continuously assess configuration drift and security gaps in cloud platforms.\n\n**Detection measures:**\n- Deploy UEBA (User and Entity Behavior Analytics) to baseline normal user activity in Salesforce and ServiceNow and alert on deviations such as mass record downloads.\n- Integrate SaaS platform logs into your SIEM and create detection rules specifically for large-volume data exports, after-hours access, and access from unexpected geolocations.\n- Conduct regular threat hunts focused on indicators of custom malware persistence within SaaS-connected endpoints and integration layers.",[12,13,14,15,16,17,18,19,20,21,22,23,24,25],"CIS Control 3 – Data Protection","CIS Control 6 – Access Control Management","CIS Control 8 – Audit Log Management","CIS Control 10 – Malware Defenses","NIST SP 800-53 AC-2 (Account Management)","NIST SP 800-53 AC-6 (Least Privilege)","NIST SP 800-53 AU-6 (Audit Record Review, Analysis, and Reporting)","NIST SP 800-53 SI-4 (System Monitoring)","NIST CSF DE.CM-1 (Network Monitoring)","NIST CSF PR.DS-5 (Protections Against Data Leaks)","GDPR Article 32 – Security of Processing","GDPR Article 33 – Notification of a Personal Data Breach","ISO\u002FIEC 27001 A.8.2 – Information Classification","ISO\u002FIEC 27001 A.12.4 – Logging and Monitoring","published","2026-08-12T22:20:24.754797+00:00","2026-08-12T22:20:24.439+00:00",{"id":7,"url":30,"slug":31,"title":32},"https:\u002F\u002Fwww.darkreading.com\u002Fcyberattacks-data-breaches\u002Flong-running-data-theft-campaign-salesforce-servicenow","long-running-data-theft-campaign-targeting-salesforce-servicenow-5c0ecb","Long-running Data Theft Campaign Targeting Salesforce, ServiceNow",[34,40,46],{"id":35,"name":36,"slug":37,"description":38,"color":39},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":41,"name":42,"slug":43,"description":44,"color":45},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":47,"name":48,"slug":49,"description":50,"color":51},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]