Research from security platform Reco reveals a single infrastructure has been scraping records from Salesforce and ServiceNow portals across multiple industries for over a year.

  • A single server (158.220.87.79) has been used to orchestrate attacks across multiple industries.
  • The campaign targets high-value customer portals like Salesforce and ServiceNow.
  • The threat actor's activity has been ongoing for more than a year.

A significant cybersecurity threat has been uncovered by the agent security platform Reco. According to their latest research, a single piece of infrastructure has been systematically pulling records out of Salesforce and ServiceNow customer portals. This sophisticated operation has been active for more than a year, affecting various industries globally.

The threat actor's activity, which Reco has dubbed the 'City Forum' campaign, is linked to a specific domain tied to the attacker's IP address. Investigations trace the entire operation back to a single server: 158.220.87.79, which serves as the central hub for this massive data-scraping effort.

Why This Matters

BozokMedia analysis shows that this campaign highlights the critical danger of cross-domain privilege escalation. By targeting widely used SaaS platforms like CRM (Salesforce) and ITSM (ServiceNow), the attacker can bypass traditional perimeter defenses and access highly sensitive corporate and customer data directly through legitimate-looking portal interactions.

Identity exposure is the primary mechanism that unlocks active attack paths in modern cloud environments.

The implications are vast. As companies migrate more critical business processes to the cloud, the surface area for identity-based attacks expands. This 'City Forum' campaign demonstrates that attackers are no longer just looking for vulnerabilities in software, but are exploiting the way identities are managed and accessed across different service domains.

Historical Background

Historically, cyberattacks focused on infiltrating private networks via malware. However, the landscape has shifted toward 'Identity-Centric' attacks. In the modern SaaS era, attackers prioritize stealing or misusing credentials to navigate through cloud portals, making them much harder to detect using traditional network monitoring tools.

Did You Know?: Most modern data breaches involve the misuse of legitimate credentials rather than the exploitation of software bugs.

Frequently Asked Questions

Question 1: What is the 'City Forum' campaign?
Answer: It is a cyberattack campaign identified by Reco that scrapes data from Salesforce and ServiceNow portals using a single server.

Question 2: How can organizations protect themselves?
Answer: Implementing strict Identity and Access Management (IAM) policies and continuous identity monitoring is essential.