Salesforce and ServiceNow attacks expose new API risks
Researchers say ‘City-Forum’ campaign targets Salesforce and ServiceNow, possibly tied to ShinyHunters.
Salesforce and ServiceNow systems are under a new wave of attacks, with user data left exposed, according to researchers at Reco. The campaign, which the firm has dubbed “City-Forum,” appears to share similarities with the work of the extortion group ShinyHunters, but it also breaks new ground in how it breaks in.
A familiar foe, with a new twist
Reco’s researchers say the attack resembles those previously carried out by ShinyHunters, a group that has been unusually active this year. The group was tied to attacks on dating sites in January and on Oracle in June, and there are fears they may have turned their attention to enterprise software. But this time, the attacker took a different path, penetrating systems through the UI-API layer — an entry point that Reco says it had not previously seen used in such campaigns. The attacker also built its own custom toolset for the job, rather than relying on publicly available utilities.
Targeting an undocumented endpoint
A particularly notable aspect of the campaign is its focus on a native ServiceNow Service Portal search endpoint. According to Reco, this endpoint has almost no online documentation and few, if any, well-known open-source tools designed to interact with it. That suggests the attacker did significant reconnaissance and development work to find and exploit this specific weakness. Reco says the attacker studied the services to map out common data-leak vectors — a sign, the firm argues, of an advanced and methodical approach.
What’s at stake
Both Salesforce and ServiceNow are widely used by enterprises to manage customer relationships, IT services, and other critical business functions. A compromise of these systems could expose sensitive customer data, internal records, or other confidential information. Reco’s findings indicate that the attacker was able to access user data, though the full scope of the exposure is not yet clear.
Why credentials are the weak link
Regardless of who is behind the attack or how they pulled it off, Reco’s warning carries a clear message for organizations: be increasingly careful about who you give login credentials to. The campaign underscores that even well-defended platforms can be vulnerable if an attacker gains legitimate access through compromised or misused credentials.
The bigger picture
This incident fits into a broader pattern of rising extortion-driven attacks, with groups like ShinyHunters becoming more aggressive and innovative. The use of a custom toolset and an undocumented endpoint suggests that attackers are willing to invest heavily in finding novel ways into enterprise systems. For security teams, the lesson is to monitor not just for known attack patterns but also for signs of unusual activity in API traffic and user authentication logs.
What this means for you
If your organization relies on Salesforce or ServiceNow, it’s worth reviewing your security posture now. That includes auditing user accounts, enforcing multi-factor authentication, and watching for suspicious activity in API logs. Reco’s findings indicate that the attackers are not just spraying credentials at random but are targeting specific, high-value systems. Proactive monitoring and strict access controls could be the difference between a near-miss and a full-blown data breach.
Sources
- CSO Online Original source
Continue Reading
Cloudflare Vows Quantum-Proof TLS Shift
Cloudflare says it will issue post-quantum TLS certificates using Merkle Tree Certificates, targeting Q1 2027 after acquiring a GlobalSign root.
AI-Discovered Flaws Skew Toward RCE
Google's threat intelligence unit reports AI-found vulnerabilities are far more likely to enable remote code execution than other disclosed flaws.
Teen's Auth Flaw Opened Titan's Data Vault
A 16-year-old researcher bypassed Microsoft's Titan analytics by exploiting an unverified JWT and was paid a $5,000 bounty.