# Your CRM Was the Target All Along: Inside the City-Forum Data Theft Campaign


Sometime around March 2025, a threat actor quietly set up shop inside enterprise SaaS environments and started draining them. Not a smash-and-grab ransomware hit — the kind that makes headlines and triggers incident response retainers. Something quieter. Patient. Methodical. The campaign researchers are calling "City-Forum" has been siphoning data from organizations using Salesforce and ServiceNow, and the fact that it took this long to surface publicly tells you something important about the blind spots most companies still have in their cloud security posture.


## The Platforms Attackers Chose Are Not Random


Salesforce and ServiceNow aren't just software. For most mid-to-large enterprises, they're the connective tissue of the business — customer records, sales pipelines, internal IT ticketing, employee onboarding workflows, vendor contracts, incident reports. The kind of data that, assembled correctly, gives an adversary a comprehensive map of how an organization operates, who its customers are, and what its vulnerabilities look like.


Ransomware actors understood years ago that encrypting files was a blunt instrument. The smarter play — the one espionage-focused groups and sophisticated criminal outfits have been migrating toward — is persistent access to high-value data repositories. Salesforce and ServiceNow are exactly that: structured, searchable, accessible from anywhere with valid credentials, and frequently under-monitored compared to traditional endpoints.


City-Forum's operators clearly understood this. The campaign reportedly uses custom tooling, which immediately separates it from the commodity malware crowd and points toward either a nation-state actor or a well-resourced criminal group that invests in operational security. Off-the-shelf tools leave signatures. Custom tooling means someone spent real engineering hours building something purpose-built to stay under the radar inside these specific platforms.


## How SaaS Became the Unguarded Flank


There's a recurring pattern in enterprise security architecture: defenses cluster around what organizations used to worry about, while attackers move to where organizations are going.


For a decade, the industry poured investment into endpoint detection and network monitoring. Meanwhile, business-critical data steadily migrated into SaaS platforms that many security teams treat as someone else's problem — the vendor's responsibility, secured-by-default, outside the traditional perimeter. The logging and behavioral monitoring that mature security operations have for Windows endpoints simply doesn't exist at the same fidelity for Salesforce API activity or ServiceNow data exports.


This creates an environment where an attacker with valid credentials — obtained through phishing, credential stuffing, purchased access, or compromised OAuth tokens — can query and exfiltrate enormous amounts of structured data with minimal noise. Normal Salesforce usage looks a lot like quiet exfiltration. A sales rep pulling thousands of contact records before leaving for a competitor looks identical to a threat actor doing the same thing. Without purpose-built SaaS security tooling and properly tuned alerting, both look like normal business activity.


City-Forum has apparently been exploiting exactly this gap for months. Multi-sector targeting reinforces the point — this isn't a campaign with a specific industry grudge. It's a campaign that goes where valuable data lives, and valuable data lives in Salesforce and ServiceNow across virtually every vertical.


## What Custom Tooling Reveals


The detail that stands out most in what's known about City-Forum is the custom tooling. This costs real resources. Someone wrote code specifically to interact with these platforms in ways that avoid detection — likely abusing legitimate API functionality, blending into normal traffic patterns, avoiding the obvious tripwires.


This isn't a script kiddie operation. The profile matches either a nation-state with collection mandates across industry sectors, or a criminal organization operating in the access broker or corporate espionage space — selling exfiltrated data to competitors, short-sellers, or nation-states who want the intelligence without the operational risk of running the campaign themselves.


The March 2025 start date is worth noting. That's five-plus months of activity before public attribution. During that window, affected organizations were generating incident response costs they didn't know about yet: stolen customer data, compromised business intelligence, exposed internal processes. The damage accumulates invisibly.


## What Defenders Need to Do Differently


The instinct after reading about campaigns like this is to focus on the detection side — what signatures to look for, what indicators of compromise to hunt. That matters, but it misses the structural problem. If your organization doesn't have visibility into SaaS API activity at the query level, you're not going to catch City-Forum by hunting for it. You won't see it at all.


The remediation path has a few clear components. First, SaaS security posture management tools that provide visibility into what's actually being accessed and exported — Salesforce has native event monitoring; ServiceNow has logging capabilities that most organizations leave at defaults or don't ingest into their SIEM. Second, review of OAuth applications and connected integrations with access to these platforms — third-party apps with excessive permissions are a persistent entry vector that gets less attention than phishing. Third, conditional access policies that flag anomalous export behavior: a service account querying 50,000 records at 2 AM is not normal, regardless of whether the credentials are technically valid.


The multi-sector scope also matters for threat intelligence sharing. If your sector has an ISAC, City-Forum indicators are exactly what those channels exist to distribute quickly.


---


## HackWire Analysis


City-Forum fits into a trend that deserves more sustained coverage than it gets: the systematic targeting of enterprise SaaS platforms by sophisticated threat actors who correctly identified that most organizations have a monitoring gap between their traditional security stack and their cloud application layer.


What's notable here isn't just the campaign itself — it's what it represents about attacker calculus in 2025 and 2026. Endpoint detection has matured. Network traffic analysis has matured. The return on investment for well-resourced attackers has shifted toward environments where defenders are still catching up: SaaS platforms, cloud configuration interfaces, identity providers. The combination of Salesforce and ServiceNow as targets is particularly significant because together they often hold both external-facing customer data and internal operational intelligence, giving a single successful campaign enormous intelligence yield.


The "multi-sector" framing is also worth scrutinizing. Broad targeting can indicate a financially motivated operation — access brokers selling to multiple buyers — or it can indicate an intelligence-gathering campaign with catholic collection priorities. Nation-state actors increasingly operate with collection mandates that span industries rather than focusing narrowly on defense or government. If this is espionage rather than financially motivated crime, the long dwell time and custom tooling profile fits well with known advanced persistent threat behavior.


What other coverage is likely missing: the question of initial access. Custom tooling and patient exfiltration still require a door in. Whether City-Forum is entering through phishing for privileged credentials, compromising OAuth integrations, exploiting misconfigurations in Salesforce community portals (a historically productive attack surface), or buying access from initial access brokers changes the remediation priority significantly. The initial access vector is often the detail that gets elided from early campaign reporting and is often the most actionable one for defenders.


Organizations with Salesforce Shield or ServiceNow's advanced logging should be pulling their event logs and looking backward to March 2025.


— HackWire Editorial


---


## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)