Bottom line: Reco has identified an attack campaign called “City-Forum” that exfiltrates data from Salesforce and ServiceNow systems via a previously unknown UI API access path and shows methodological parallels to the ShinyHunters group.
Security researchers at Reco have identified a new attack campaign called “City-Forum” that specifically targets data from Salesforce and ServiceNow environments. The approach shows parallels to the extortion group ShinyHunters, which had already attacked dating platforms and Oracle in 2025.
According to Reco, the current wave of attacks is directed at data sets stored in Salesforce and ServiceNow systems. Reco named the campaign “City-Forum” after a domain associated with the attackers’ IP address. The attack path is notable: the perpetrators gained entry via the UI API layer — an attack vector that Reco states it had not previously observed. In addition, they used a native ServiceNow Service Portal search endpoint for which little documentation or known open-source tools exist online. The attackers deployed a purpose-built toolset for this.
Based on methodological similarities, Reco attributes the campaign to the ShinyHunters group, without confirming this with absolute certainty. ShinyHunters was already active multiple times in 2025, including in January against dating platforms and in June against Oracle. If the suspicion is confirmed, the group would have found a new, business-critical target in the SaaS space with Salesforce and ServiceNow.
The finding is relevant for CISOs because both platforms frequently manage business-critical customer and ticket data and are deeply integrated into existing corporate processes. The fact that, according to Reco, the attackers analyzed the services in advance and mapped various common data exfiltration vectors points to a methodical, deliberate approach rather than an opportunistic attack.
Reco draws a general recommendation from this: regardless of the exact attribution of the perpetrators and the precise technical attack chain, organizations should more strictly review the assignment and control of access credentials for SaaS platforms such as Salesforce and ServiceNow. This includes, in particular, monitoring unusual access at the API and portal levels as well as regularly reviewing which accounts have access to sensitive endpoints.
Source: www.csoonline.com · Published August 14, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.