Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
The article presents minimal operational detail — no attribution, no victim names, no technical indicators, no sample code or IOCs, and no evidence of detection or mitigation — while naming a campaign and asserting its persistence and scope.
View original on darkreading.comOverview
A persistent cyber-espionage campaign dubbed 'City-Forum' has been operating since at least March 2025, using custom tooling to steal data from organizations using Salesforce and ServiceNow platforms.
TL;DR
- Campaign active since at least March 2025
- Targets Salesforce and ServiceNow users across multiple sectors
- Relies on custom-built tooling for data exfiltration
Key Stats
March 2025
earliest observed activity
No earlier timeline provided; no attribution or duration beyond 'at least'
Questions Answered
Narrative Frame
strategic ambiguity
Spin Score
75%
Emphasizes existence and longevity of a threat while minimizing absence of verifiable forensic detail, attribution, or actionable intelligence.
What the story wants you to believe
That a new, persistent, and operationally distinct threat targeting critical SaaS platforms is already underway — warranting immediate attention and resource allocation.
What it makes harder to question
Whether the campaign label reflects coherent adversary behavior or is instead a premature aggregation of unrelated incidents.
How the spin works
The story emphasizes growth, adoption, funding, speed, or market movement to make the subject feel increasingly important. Watch for loaded terms such as long-running, custom tooling, targeting. The distribution reads as editorial reporting. A pressure point: Attribution (actor identity or motivation).
Who Benefits If This Frame Spreads
Dark Reading editorial team
Establishes authority as an early source on emerging threats and drives engagement with cybersecurity professionals seeking situational awareness.
Naming and dating a campaign without requiring full attribution or public IOCs allows rapid publication while preserving perceived expertise and timeliness.
The Frame
Authoritative threat reporting — positioning the story as timely, credible reconnaissance rather than speculative or unverified chatter.
Missing Context
- Attribution (actor identity or motivation)
- Technical specifics (C2 infrastructure, malware samples, exploit vectors)
- Evidence of successful exfiltration (logs, screenshots, forensic validation)
SpinGraph
How this belief gets built
Claim → Frame → Beneficiary → Gap → AI Risk
By naming and dating the campaign without providing proof, the story makes it feel like a known entity — something analysts and defenders should already be tracking — even though no concrete evidence is offered to confirm its coherence
- Claim
The 'City-Forum' campaign has been active since at least March
The 'City-Forum' campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.
- Frame
Key details stay obscured
Authoritative threat reporting — positioning the story as timely, credible reconnaissance rather than speculative or unverified chatter.
- Beneficiary
Establishes authority as an early source on emerging threats
Dark Reading editorial team — Establishes authority as an early source on emerging threats and drives engagement with cybersecurity professionals seeking situational awareness.
- Gap
Attribution (actor identity or motivation)
- AI Risk
AI may repeat the headline as fact
A cyber-espionage campaign called 'City-Forum' has targeted Salesforce and ServiceNow users since March 2025 using custom tools.
Claim Ledger
| Claim | Evidence | Verification | Risk | Evidence Gaps |
|---|---|---|---|---|
| The 'City-Forum' campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling. | None beyond the bare assertion — no citations, no attribution, no technical detail, no corroborating source. | Needs Evidence | High | Publicly released IOCs (hashes, domains, IPs); Attribution report or vendor advisory; Forensic validation from incident response logs or telemetry; Named victims or sector-specific examples |
The 'City-Forum' campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.
evidence: None beyond the bare assertion — no citations, no attribution, no technical detail, no corroborating source.
"The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling."
Evidence Gaps
- Publicly released IOCs (hashes, domains, IPs)
- Attribution report or vendor advisory
- Forensic validation from incident response logs or telemetry
- Named victims or sector-specific examples
Fact Check Signals
0 of 1 claim matched · confidence: low · checked August 13, 2026
The 'City-Forum' campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.
Language Heatmap
Loaded terms that carry the frame beyond the facts.
Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Carries emotional weight beyond the underlying fact.
Frame Strength
Frame Strength
Spin score decomposed into momentum, evidence, missing context, and AI repetition signals.
Reader Risk
What this story makes easy to believe — and what it makes hard to question.
Source Role & Intent
Dark Reading · Media
Counter-Frames
Brand Frame
Authoritative threat reporting — positioning the story as timely, credible reconnaissance rather than speculative or unverified chatter.
Media / Reader Counter-Frame
Framed as unattributed threat hype — a placeholder name applied prematurely to isolated incidents without consensus or forensic rigor.
Regulatory Counter-Frame
Framed as insufficient disclosure — lacking transparency about methodology, sources, or confidence level required for responsible disclosure to affected vendors or agencies.
AI Summary Frame
Dropped nuance: AI may treat 'City-Forum' as a confirmed APT group rather than an unattributed label applied to observed activity.
Missing Voices
Questions Not Answered
- Which specific organizations were compromised?
- What data was exfiltrated and in what volume?
- Who is behind the campaign — nation-state, criminal group, or other?
Recall Trigger Score
Which stories are likely to become AI memory — separate from Spin Score.
29
Trigger score 0
Not tracked — low-authority source, weak claim, or no durable entity.
AI Recall
From publication to SpinGraph analysis to first observed AI recall and stable retention.
What AI Will Probably Repeat
"A cyber-espionage campaign called 'City-Forum' has targeted Salesforce and ServiceNow users since March 2025 using custom tools."
Concern: AI systems may repeat 'since March 2025' and 'custom tooling' as established facts, omitting that these are unverified assertions with no supporting evidence in the source.
-
Published
Aug 12, 2026
-
Ingested
Aug 13, 2026
-
SpinGraph Created
Aug 13, 2026
-
First Observed AI Recall
Pending
Monitoring scheduled
-
Stable Recall
—
Awaiting retention signal
Recall Check Log
No checks yet — recall tracking is opt-in per story.
─── GEOGrow AI Recall Layer ───
AI Recall Tracking
Monitoring scheduled. No LLM recall detected yet.
This story has not yet appeared in tested AI answers. Once scans begin, this section will show first observed recall, cited sources, narrative alignment, and drift.
node_id=sts_long_running_data_theft_campaign_targeting_sales
Ask AI about this story
Opens with the SpinGraph .md URL and structured context — one click, prompt included.
Narrative Entities
More from Dark Reading
View all →- Belgium's eID Authentication Opens Citizen Accounts to RCE
- 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
- Walmart Leaders Transform Security Operations Without Going Bananas
- Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
- Walmart's "Trusted Agent" Approach to Purple Teaming
- Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA
Markdown (.md) · JSON-LD schema (.json) · Machine-readable for AI & GEO