Salesforce, ServiceNow data targeted in ‘City-Forum’ attacks
Researchers at Reco say “City-Forum” attacks are targeting data stored in Salesforce and ServiceNow systems, exposing user information. Reco links the campaign to extortion group ShinyHunters based on similarities, noting a new UI-API entry point and custom tooling. The attackers also target a ServiceNow Service Portal search endpoint.
How this was made

The 30-second read
Why it matters
If confirmed, the UI-API and Service Portal search endpoint attack paths raise customer data exposure concerns and could trigger incident-response, legal, and security-investment costs, plus reputational damage.
Market read
This is threat-intel about potential data exposure in two major enterprise software platforms, but it lacks confirmed breach scope or financial figures.
What to watch
Traders may discount the move if vendors quickly issue mitigations, if logs show no compromise, or if the described endpoints are not widely used in production.
Background
Reco attributes a new extortion-style campaign, dubbed ‘City-Forum,’ to attacks resembling ShinyHunters, targeting Salesforce and ServiceNow systems.
Ticker impact
The article says records held in Salesforce systems are under attack, exposing user data via a UI-API layer intrusion.
Moderate downside bias for risk-sensitive trading until incident details and remediation are clarified.
The piece is threat-intel focused, with no confirmed breach scope or financial impact, but it directly flags Salesforce as a compromised target.
The article reports ServiceNow systems are targeted in the ‘City-Forum’ campaign, including a native Service Portal search endpoint.
Mild-to-moderate negative bias, with volatility tied to any follow-up confirmation and mitigation updates.
The article identifies ServiceNow as a target and describes an attack path, but provides no confirmed customer impact, breach confirmation, or remediation timeline.
Market effects
Highlights elevated cyber risk for enterprise SaaS platforms and may increase scrutiny of UI/API and portal endpoints.
No specific regional market linkage provided.
Extortion-group style campaigns suggest cross-border threat persistence for cloud software providers.
Counterpoint
The report is based on researchers’ observations and may not confirm a successful breach or material customer data loss, limiting immediate equity impact.
Key entities
- companySalesforce
Named as having records in systems under attack, with exposure risk tied to the UI-API layer.
- companyServiceNow
Named as a target, including a native Service Portal search endpoint with little public documentation.
- researcherReco
Researchers reporting the campaign details and attack vector observations.
- threat_actorShinyHunters
Extortion group cited as having similar past exploits and active this year.

