# The Enterprise Portal Problem: How "City-Forum" Attackers Are Draining Salesforce and ServiceNow
The breach notification nobody wants to receive lands in your inbox and says something along the lines of: "unauthorized access to our customer portal." The company used Salesforce or ServiceNow. The data is gone. And the attacker didn't need a zero-day to get it.
That's the pattern behind a wave of intrusions researchers are tracking under the "City-Forum" label — a campaign specifically hunting enterprise self-service portals built on two of the most dominant SaaS platforms in corporate infrastructure. The attacks aren't spectacular. That's precisely what makes them dangerous.
## What These Portals Actually Are — and Why They Bleed
Salesforce Experience Cloud and ServiceNow's customer-facing portals exist for a legitimate reason: companies want employees, partners, and customers to access ticketing, knowledge bases, and case management without calling a human. They're designed for broad access. The problem is that "broad" has a tendency to become "unrestricted" when configuration is rushed or misunderstood.
Both platforms offer granular permission controls. Both are routinely misconfigured in the wild. ServiceNow's Knowledge Base articles, for instance, can be marked as publicly accessible at the article level, the category level, or the KB level — and each layer has its own access control setting. Miss one toggle and your internal IT runbooks, HR procedures, or network architecture documentation is sitting in front of anyone who knows where to look.
Salesforce's guest user permissions follow a similar pattern. Experience Cloud sites grant unauthenticated visitors a "guest user" profile, and that profile can be — and frequently is — inadvertently granted object-level read access to records that should never leave the org. In some cases, security researchers have found guest users able to query customer records, contracts, or internal files via the standard Salesforce API.
City-Forum attackers appear to have built tooling specifically around enumerating these misconfigured surfaces. The name likely reflects what they're hunting: community portals and self-service hubs standing up for municipalities, utilities, healthcare networks, and mid-market enterprises that stood up these portals quickly and never came back to audit the permissions.
## The Mechanics of the Grab
The attack pattern reported across City-Forum incidents follows a recognizable playbook, even if the specific tooling varies:
1. Reconnaissance on the portal subdomain. Attackers identify Experience Cloud or ServiceNow portals via certificate transparency logs, Shodan, or simple Google dorking. Both platforms leave distinctive fingerprints.
2. Anonymous API enumeration. The attacker hits the platform's API endpoints without authenticating. For Salesforce, that's the REST API with the guest session token the portal automatically issues. For ServiceNow, it's unauthenticated GET requests to the /api/now/table/ endpoint or the Knowledge Base widget endpoints.
3. Bulk extraction. Once they've confirmed which objects and records are accessible, they scrape — systematically pulling CRM records, case histories, employee data, or internal documentation.
4. Exfiltration and monetization. The data ends up for sale, used in targeted phishing, or held for extortion depending on who's behind the specific incident.
No vulnerability is exploited in the traditional sense. No CVE is required. The platform is functioning exactly as configured — just configured wrong.
## Who's Getting Hit
The "City-Forum" framing suggests the campaign has particular focus on organizations running public-sector-adjacent portals: city governments, healthcare systems, utilities, school districts. These entities often adopted Salesforce or ServiceNow during a rapid digital transformation push — frequently during or after the pandemic — and their IT teams either lacked the SaaS security expertise or the bandwidth to audit portal configurations post-deployment.
This isn't a random coincidence. Public sector organizations tend to have:
Mid-market enterprises in the same boat — portals stood up by a system integrator two years ago, now running unattended — are equally exposed.
## The Deeper Problem Nobody Wants to Admit
Here's what most coverage of SaaS misconfiguration attacks underplays: the vendors share responsibility here, and they know it.
Both Salesforce and ServiceNow have spent years marketing the ease of deploying these portals. "Low-code, out-of-the-box, self-service" — all phrases that implicitly promise that a non-security person can manage it. The permission models are powerful but they're also genuinely complex, and the default settings have historically erred on the side of permissiveness rather than safety.
ServiceNow pushed an update in 2023 that defaulted new Knowledge Base installs to require login for public article access — a correction in the right direction. Salesforce has issued security advisories around guest user permissions multiple times. But the installed base of organizations running legacy configurations that predate these changes is enormous. Advisories don't retroactively fix misconfigured tenants.
The attackers running City-Forum operations understand this perfectly. They're not racing against patch cycles. They're running against organizations' configuration review backlogs, which for many shops is effectively infinite.
---
## HackWire Analysis
City-Forum sits at the intersection of two trends that security teams need to track together: SaaS sprawl and the commoditization of portal enumeration tooling.
The broader pattern here isn't about Salesforce or ServiceNow specifically — it's about the entire category of enterprise platforms that offer public or semi-public portals as a feature. Jira Service Management, Zendesk, HubSpot customer portals, Confluence spaces — every one of these has a permissioning model complex enough to misconfigure at scale, and every one of them is being probed by actors who have built automated tooling to find the gaps.
What's missing from most coverage of these incidents is attribution context. "City-Forum" is a campaign descriptor, not a named threat actor with established infrastructure. That matters because it suggests this capability has diffused — multiple independent operators are running variations of the same playbook, not a single sophisticated group. When a technique commoditizes, the volume of attacks increases sharply and the targets get less selective.
For defenders, the immediate priority isn't waiting for a vendor advisory. Pull a report of every object and field accessible to the guest user profile in Salesforce Experience Cloud today. Run ServiceNow's built-in security health check against your Knowledge Base configurations. If you used a system integrator to deploy either platform, assume they configured permissions for ease-of-use, not security, and verify accordingly.
Organizations in healthcare, utilities, and local government specifically should treat this as active threat rather than theoretical risk. If your portal has been live for more than 18 months without a permissions audit, you're already behind.
The attackers running City-Forum campaigns are not sophisticated. They're patient and automated. The organizations that will avoid being the next breach notification are the ones who find their misconfiguration before the scanner does.
— HackWire Editorial
---
## Related Coverage