Table of Contents
Summary
A single server used the same IP address and tooling fingerprint to scrape Salesforce and ServiceNow customer portals undetected for over 18 months, a campaign researchers at Reco have named City Forum. The incident shows why traffic volume alone is an unreliable signal for detecting attacks, and why behavioral analysis, which looks at how traffic behaves rather than how much of it there is, catches patient, low and slow attackers that volume-based defenses miss.
For more than a year, one server has quietly pulled records out of Salesforce and ServiceNow customer portals across a wide range of industries, and almost nobody noticed. There was no zero-day exploit involved, no dramatic smash-and-grab moment. Just one IP address and one tool, doing the same thing over and over, long enough that it stopped looking suspicious to anyone watching.
Researchers at Reco have named the operation the City Forum campaign, tracing it back to a single commodity VPS server hosted in Germany. Every request from that server carries the same signature, the default user agent of Go’s networking library, which tells us this is a purpose-built tool rather than something run casually through a browser. Passive DNS records show that the infrastructure behind it has been active since March 2025.
Stories like this one still catch my attention after all these years in this industry, mostly because of how simple the method is. Eighteen months is a long time for anything to go unnoticed on the open internet, and it’s a particularly long time for the exact same source, using the exact same tool, to keep operating without anyone stepping in.
Why Low and Slow Attacks Slip Past Traditional Detection
What strikes me most about this case is the lack of sophistication of the attacker. This is a story about persistence quietly outlasting detection, and it’s a pattern I see far too often across our industry, whether the target is a SaaS portal or a network edge under a DDoS attack.
Most security tools are still built primarily to catch spikes: a sudden surge in traffic, an unusual volume from an unfamiliar source, activity that looks like an attack because it behaves the way we’ve trained our systems to expect an attack to behave, fast, loud, and over quickly. An attacker who instead moves slowly and consistently rarely trips those wires, because a single IP address requesting data at a measured, steady pace for a year and a half doesn’t look like an attack in progress. Day after day, it just looks like normal traffic, until someone finally takes a closer look and connects the dots.
None of this is new. Low and slow has been a known tactic for years. It keeps working simply because so much of our industry is still tuned to catch the wrong signal.
Why Traffic Volume Is the Wrong Signal for Detecting Threats
I understand the instinct to measure threats by volume. Big spikes are easy to see, and easy to build alerts around. But the City Forum campaign is a good reminder that scale and speed were never reliable proxies for risk.
An attacker willing to be patient doesn’t need to be loud. They just need to stay consistent enough to avoid standing out, and quiet enough that nobody stops to ask why the same source has been showing up, day in and day out, for over a year.
How Behavioral Analysis Catches What Volume-Based Detection Misses
This is exactly why we built SmartWall ONE™ around behavioral packet analysis rather than traffic flow baselines. A baseline approach essentially asks whether traffic looks bigger or faster than what’s typical. Behavioral analysis asks something different: whether the traffic is behaving the way it should, independent of how large or fast it happens to be. A single IP address making requests against a portal for 18 straight months, no matter how quiet each individual request looks on its own, is a behavioral anomaly rather than a volume one. That distinction is often the difference between catching an attacker in the first moments of activity and catching them a year and a half later, or after your website or service is already down!
What This Means for Anyone Defending Infrastructure
The City Forum campaign won’t be the last low and slow operation to run for months before anyone notices, and as long as our industry keeps tuning defenses primarily to catch spikes, patient attackers will keep finding plenty of room to operate underneath them.
The fix isn’t simply dialing up sensitivity to volume. It’s a more fundamental shift toward recognizing behavior that doesn’t belong, regardless of how quiet it is or how long it’s been running. That’s the standard I hold our own technology to, and it’s the standard I’d like to see more of our industry move toward. Eighteen months is a long time for anything to go unnoticed. It shouldn’t have taken that long.
FAQ
City Forum is the name Reco researchers gave to a scraping operation that pulled records from Salesforce and ServiceNow customer portals for more than 18 months, using a single server with a consistent IP address and tooling fingerprint.
The campaign relied on a slow, steady pace of activity from a single source rather than a sudden spike in traffic. Most detection tools are built to flag unusual volume or speed, so consistent, low-volume activity from the same source didn’t trigger the alerts it might have if it had been faster or larger.
A low and slow attack is an approach where an attacker deliberately keeps their activity quiet and steady over a long period, rather than generating a large or fast burst of traffic, specifically to avoid detection systems that are tuned to catch spikes in volume.
Traffic volume detection flags activity based on how much traffic there is or how fast it’s arriving. Behavioral analysis instead looks at whether the traffic itself is behaving the way it should, which allows it to catch patient, low-volume attackers that volume-based tools tend to miss.
The City Forum campaign targeted SaaS portals rather than DDoS infrastructure, but the underlying detection challenge is the same one Corero built SmartWall ONE to address: attackers who avoid detection by staying quiet and consistent rather than loud and fast.

