Threat Brief — 2026-08-13 — Portal Data Theft & Android NFC Relay
Executive summary. Two active campaigns deserve attention today. The "City-Forum" operation has been quietly exfiltrating data from Salesforce Experience Cloud and ServiceNow customer portals since at least March 2025, exploiting anonymous-access misconfigurations across multiple sectors. Separately, a new Android malware combo pairs the WindRelay NFC relay tool with SpyNote to steal live contactless card data and even take out loans in victims' names.
Top items
- "City-Forum" data-theft campaign targets Salesforce and ServiceNow portals. Active since at least March 2025, this campaign uses custom tooling to harvest data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. The multi-sector targeting and longevity suggest a well-resourced operation exploiting persistent misconfigurations rather than zero-days — organisations running these portals should audit anonymous-access scopes immediately. (src: BleepingComputer, DarkReading)
- WindRelay Android NFC relay malware paired with SpyNote steals live card data. A new Android malware combo uses WindRelay to relay NFC payment data to attackers in real time while SpyNote provides remote administration. The combination enables fraudsters to conduct contactless transactions with victims' cards and even take out loans using stolen device access. This is a consumer-facing threat but enterprises with BYOD programs should alert staff. (src: BleepingComputer)
Themes
Portal and API exposure as the soft underbelly. City-Forum doesn't rely on novel exploits — it weaponises overly permissive anonymous access on widely deployed SaaS portals (Salesforce, ServiceNow). This mirrors the broader pattern seen this month where enterprise edge systems hold while interior services and customer-facing portals remain under-secured, consistent with the Picus Blue Report findings from earlier this week.
Mobile as a live payment attack surface. WindRelay's real-time NFC relay capability represents an escalation from static card skimming to live transaction fraud, combining physical-proximity NFC abuse with established RAT tooling (SpyNote) for broader device control.
