---
title: "Long-running Data Theft Campaign Targeting Salesforce, ServiceNow | SpinGraph: Strategic ambiguity"
description: "SpinGraph analysis of Dark Reading's Long-running Data Theft Campaign Targeting Salesforce, ServiceNow story: strategic ambiguity, The Fog, Spin Score 75%, mod…"
	canonical: "https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow"
html: "https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow"
json: "https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow.json"
markdown: "https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow.md"
keywords: ["City-Forum", "Salesforce", "ServiceNow", "The Fog", "narrative intelligence"]
date: "2026-08-12T21:08:54+00:00"
modified: "2026-08-13T02:22:30.854258+00:00"
json_ld: |
  {"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://stuffthatspins.com/#organization","name":"Stuff That Spins","url":"https://stuffthatspins.com/","description":"Know the moment AI knows your story. Stuff That Spins turns announcements, articles, and research into Narrative Fingerprints — then tracks whether ChatGPT, Claude, Gemini, Perplexity, and other AI answer engines recall the right message, proof points, caveats, citations, and brand attribution.","logo":{"@type":"ImageObject","url":"https://stuffthatspins.com/images/logo.png"},"sameAs":[]},{"@type":"NewsArticle","@id":"https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow#article","headline":"Long-running Data Theft Campaign Targeting Salesforce, ServiceNow","alternativeHeadline":"Long-running Data Theft Campaign Targeting Salesforce, ServiceNow | SpinGraph: Strategic ambiguity","description":"SpinGraph analysis of Dark Reading's Long-running Data Theft Campaign Targeting Salesforce, ServiceNow story: strategic ambiguity, The Fog, Spin Score 75%, mod…","datePublished":"2026-08-12T21:08:54+00:00","dateModified":"2026-08-13T02:22:30.854258+00:00","url":"https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow","mainEntityOfPage":{"@type":"WebPage","@id":"https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow"},"isAccessibleForFree":true,"inLanguage":"en-US","articleSection":"cybersecurity","keywords":"City-Forum, Salesforce, ServiceNow, data theft, cyber-espionage","author":{"@type":"Organization","name":"Dark Reading","url":"https://www.darkreading.com/rss.xml"},"publisher":{"@id":"https://stuffthatspins.com/#organization"},"citation":"https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow","about":[{"@type":"Thing","name":"City-Forum"},{"@type":"Thing","name":"Salesforce"},{"@type":"Thing","name":"ServiceNow"},{"@type":"Thing","name":"data theft"},{"@type":"Thing","name":"cyber-espionage"}],"mentions":[{"@type":"Organization","name":"Dark Reading"},{"@type":"Organization","name":"Salesforce"},{"@type":"Organization","name":"ServiceNow"}],"abstract":"Campaign active since at least March 2025 Targets Salesforce and ServiceNow users across multiple sectors Relies on custom-built tooling for data exfiltration"},{"@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Stuff That Spins","item":"https://stuffthatspins.com/"},{"@type":"ListItem","position":2,"name":"Long-running Data Theft Campaign Targeting Salesforce, ServiceNow","item":"https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow"}]},{"@type":"AnalysisNewsArticle","@id":"https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow#spin-analysis","headline":"Spin Analysis: strategic ambiguity","description":"Emphasizes existence and longevity of a threat while minimizing absence of verifiable forensic detail, attribution, or actionable intelligence.","about":{"@type":"DefinedTerm","name":"strategic ambiguity","description":"Authoritative threat reporting — positioning the story as timely, credible reconnaissance rather than speculative or unverified chatter.","termCode":"The Fog"},"additionalProperty":[{"@type":"PropertyValue","name":"Spin Score","value":75,"unitText":"percent"},{"@type":"PropertyValue","name":"Narrative Risk","value":"moderate"},{"@type":"PropertyValue","name":"AI Repetition Risk","value":"moderate"},{"@type":"PropertyValue","name":"Likely AI Summary","value":"A cyber-espionage campaign called 'City-Forum' has targeted Salesforce and ServiceNow users since March 2025 using custom tools."},{"@type":"PropertyValue","name":"Narrative Frame","value":"Authoritative threat reporting — positioning the story as timely, credible reconnaissance rather than speculative or unverified chatter."},{"@type":"PropertyValue","name":"Missing Context","value":"Attribution (actor identity or motivation); Technical specifics (C2 infrastructure, malware samples, exploit vectors); Evidence of successful exfiltration (logs, screenshots, forensic validation)"},{"@type":"PropertyValue","name":"How the Spin Works","value":"The story emphasizes growth, adoption, funding, speed, or market movement to make the subject feel increasingly important. Watch for loaded terms such as long-running, custom tooling, targeting. The distribution reads as editorial reporting. A pressure point: Attribution (actor identity or motivation)."}],"author":{"@id":"https://stuffthatspins.com/#organization"},"isPartOf":{"@id":"https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow#article"}},{"@type":"ItemList","@id":"https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow#claims","name":"Extracted Claims","itemListElement":[{"@type":"ListItem","position":1,"item":{"@type":"Claim","text":"The 'City-Forum' campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.","appearance":"The \"City-Forum\" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.","author":{"@type":"Organization","name":"Dark Reading"}}}]},{"@type":"Dataset","@id":"https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow#stats","name":"Key Statistics","description":"Extracted statistics from the source narrative","variableMeasured":[{"@type":"PropertyValue","name":"earliest observed activity","value":"March 2025","description":"No earlier timeline provided; no attribution or duration beyond 'at least'"}]}]}
---

# Long-running Data Theft Campaign Targeting Salesforce, ServiceNow

**Source:** Unknown  
**Published:** August 12, 2026  
**Original:** https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow  

## On this page

- [Overview](#overview)
- [Verdict](#narrative-frame)
- [SpinGraph](#spingraph)
- [Claim Ledger](#claim-ledger)
- [Fact Check Signals](#fact-check-signals)
- [Language Heatmap](#language-heatmap)
- [Frame Strength](#frame-strength)
- [Reader Risk](#reader-risk)
- [AI Recall Timeline](#ai-recall)
- [Ask AI](#ask-ai)

<a id="overview"></a>

## Overview

A persistent cyber-espionage campaign dubbed 'City-Forum' has been operating since at least March 2025, using custom tooling to steal data from organizations using Salesforce and ServiceNow platforms.

### TL;DR

- Campaign active since at least March 2025
- Targets Salesforce and ServiceNow users across multiple sectors
- Relies on custom-built tooling for data exfiltration

### Key Stats

- **March 2025** — earliest observed activity. No earlier timeline provided; no attribution or duration beyond 'at least'

<a id="spingraph"></a>

## SpinGraph

By naming and dating the campaign without providing proof, the story makes it feel like a known entity — something analysts and defenders should already be tracking — even though no concrete evidence is offered to confirm its coherence

- **Claim:** The 'City-Forum' campaign has been active since at least March
- **Frame:** Key details stay obscured
- **Beneficiary:** Establishes authority as an early source on emerging threats
- **Gap:** Attribution (actor identity or motivation)
- **AI Risk:** AI may repeat the headline as fact

<a id="fact-check-signals"></a>

## Fact Check Signals

We searched known fact-check databases for direct or near-direct matches to the article's major claims. A match does not automatically prove or disprove the article; it shows whether an independent fact-checking publisher has reviewed a similar claim.

**Signal:** 0 of 1 claim(s) matched (confidence: low).

### The 'City-Forum' campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

- No direct fact-check match found

<a id="frame-strength"></a>

## Frame Strength

- **Spin Score:** 75%
- **Evidence Strength:** 25%
- **Narrative Risk:** 75%
- **AI Repetition Risk:** 75%
- **Missing Context Risk:** 80%

<a id="narrative-mechanics"></a>

## Narrative Mechanics

**Function:** signal_momentum  

### The Spin in Plain English

By naming and dating the campaign without providing proof, the story makes it feel like a known entity — something analysts and defenders should already be tracking — even though no concrete evidence is offered to confirm its coherence

**What the story wants you to believe:** That a new, persistent, and operationally distinct threat targeting critical SaaS platforms is already underway — warranting immediate attention and resource allocation.  

**What it makes harder to question:** Whether the campaign label reflects coherent adversary behavior or is instead a premature aggregation of unrelated incidents.  

**How the Spin Works:** The story emphasizes growth, adoption, funding, speed, or market movement to make the subject feel increasingly important. Watch for loaded terms such as long-running, custom tooling, targeting. The distribution reads as editorial reporting. A pressure point: Attribution (actor identity or motivation).  

### Questions This Story Raises

- What concrete evidence supports the momentum claim?
- Is this growth meaningful, or mostly directional?
- What baseline is missing?
- Why does the main frame leave this out: “Attribution (actor identity or motivation)”?
- Why does the main frame leave this out: “Technical specifics (C2 infrastructure, malware samples, exploit vectors)”?
- What independent verification exists for the claim “The 'City-Forum' campaign has been active since at least March…”?
- What independent verification exists for the central claims?

### Who Benefits If This Frame Spreads

- **Dark Reading editorial team** — Establishes authority as an early source on emerging threats and drives engagement with cybersecurity professionals seeking situational awareness. _(Naming and dating a campaign without requiring full attribution or public IOCs allows rapid publication while preserving perceived expertise and timeliness.)_

<a id="narrative-frame"></a>

## Narrative Frame

**Tactic:** strategic ambiguity  
**Category:** The Fog  
**Spin Score:** 75%  

Emphasizes existence and longevity of a threat while minimizing absence of verifiable forensic detail, attribution, or actionable intelligence.

**Who Benefits If This Frame Spreads:** Threat intelligence team publishing initial campaign documentation.

**The Frame:** Authoritative threat reporting — positioning the story as timely, credible reconnaissance rather than speculative or unverified chatter.

### Missing Context

- Attribution (actor identity or motivation)
- Technical specifics (C2 infrastructure, malware samples, exploit vectors)
- Evidence of successful exfiltration (logs, screenshots, forensic validation)

<a id="language-heatmap"></a>

## Language Heatmap

**Language That Carries the Frame:** long-running, custom tooling, targeting

<a id="reader-risk"></a>

## Reader Risk

**Evidence Strength:** low  
Article provides no supporting evidence — no quotes from researchers, no links to reports, no IOCs, no screenshots, no victim confirmation, and no independent corroboration cited.  
**Verification Status:** Unclear / Unverified  
**Narrative Risk:** moderate  
If later shown to be misdated, misnamed, or conflated with another campaign, credibility of both Dark Reading and the underlying analysts would erode — especially if vendors dispute the claim or no IOCs ever surface.  
**AI Repetition Risk:** moderate  
**What AI Will Probably Repeat:** A cyber-espionage campaign called 'City-Forum' has targeted Salesforce and ServiceNow users since March 2025 using custom tools.  
AI systems may repeat 'since March 2025' and 'custom tooling' as established facts, omitting that these are unverified assertions with no supporting evidence in the source.  
**Counter-Frame (Media):** Framed as unattributed threat hype — a placeholder name applied prematurely to isolated incidents without consensus or forensic rigor.  
**Missing Voices:** Salesforce security team, ServiceNow Trust Center, Victim organizations, Independent threat intel firms not cited  

### Questions Not Answered

- Which specific organizations were compromised?
- What data was exfiltrated and in what volume?
- Who is behind the campaign — nation-state, criminal group, or other?

## Narrative Entities

- [City-Forum](https://stuffthatspins.com/entities/city-forum) (topic — unattributed threat campaign label)
- [Salesforce](https://stuffthatspins.com/entities/salesforce) (company — targeted SaaS platform)
- [ServiceNow](https://stuffthatspins.com/entities/servicenow) (company — targeted SaaS platform)

<a id="claim-ledger"></a>

## Claim Ledger

### primary (technical)

The 'City-Forum' campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

**Category:** safety  
**Verification:** Unclear / Unverified  
**Risk:** high  
**Evidence presented:** None beyond the bare assertion — no citations, no attribution, no technical detail, no corroborating source.  
> The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.

**Evidence Gaps:** Publicly released IOCs (hashes, domains, IPs); Attribution report or vendor advisory; Forensic validation from incident response logs or telemetry; Named victims or sector-specific examples  

<a id="ai-recall"></a>

## AI Recall

- **Published:** August 12, 2026  
- **SpinGraph summary:** The article presents minimal operational detail — no attribution, no victim names, no technical indicators, no sample code or IOCs, and no evidence of detection or mitigation — while naming a campaign and asserting its persistence and scope.  
- **Likely AI summary:** A cyber-espionage campaign called 'City-Forum' has targeted Salesforce and ServiceNow users since March 2025 using custom tools.  

## Citation Summary

This page documents the earliest publicly reported observation of the City-Forum campaign targeting enterprise SaaS platforms, serving as a baseline reference for threat intelligence timelines and vendor-specific TTP analysis.

---
*HTML version: https://stuffthatspins.com/spin/long-running-data-theft-campaign-targeting-salesforce-servicenow*
