Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Contabo

Contabo Vendor Cyber Rating & Cyber Score

contabo.com

Made-in-Germany cloud worldwide services provider - fair-priced VPS and Bare Metal available in the EU, US, UK, Singapore, Japan, India, and Australia!


Contabo A.I CyberSecurity Scoring

Contabo
Company Information
Website:https://www.contabo.com
Employees number:185
Number of followers:9,363
NAICS:5112
Industry Type:Software Development
Homepage:contabo.com
Contabo Risk Score (AI oriented)
Between 700 and 749
logo
ContaboSoftware Development
Updated:
13/08/2026
748/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Contabo Global Score (TPRM)
xxxx
logo
ContaboSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Contabo
ContaboModerate
Current Score
748Ba (MODERATE)
01000
1 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
753Before Incident
Vulnerability
12 Aug 2026Contabo
ServiceNow, Salesforce and Contabo: "City-Forum" data-theft attacks target Salesforce, ServiceNow portals

Ongoing 'City-Forum' Data Theft Campaign Targets Misconfigured Salesforce and ServiceNow Portals

748After Incident
CRITICAL-5
SALSERCON1786602506
Ongoing "City-Forum" Data Theft Campaign Targets Misconfigured Salesforce and ServiceNow Portals A persistent data theft campaign, tracked as City-Forum by SaaS security firm Reco, is exploiting misconfigured Salesforce Experience Cloud and ServiceNow customer portals to steal exposed data from organizations worldwide. The attacks, active since at least March 2025, originate from a single server (IP address 158.220.87.79, hosted by German VPS provider Contabo) and have targeted telecommunications firms, banks, enterprise software vendors, security companies, and public-sector entities. Unlike traditional exploits, the campaign does not leverage vulnerabilities in Salesforce or ServiceNow. Instead, it abuses overly permissive guest-user configurations, allowing unauthenticated access to sensitive data. The attacker consistently uses the Go-http-client/1.1 user agent and the city-forum.com domain, which has resolved to the same infrastructure for over a year. ### Attack Methods Salesforce Targets: - The attacker primarily abuses the Aura framework, sending requests to `/aura` or `/s/sfsites/aura` endpoints to enumerate publicly accessible objects (e.g., Accounts, Contacts, Cases). - Using `HostConfigController.getConfigData` and `SelectableListDataProviderController.getItems`, the attacker retrieves records from exposed objects. One victim recorded over 560,000 enumeration events from the attacker’s IP. - The campaign also targets newer Lightning Web Runtime (LWR) sites, exploiting Salesforce’s UI API via GraphQL requests to `/webruntime/api/services/data/{version}/graphql` a technique not observed in public attack tools like AuraInspector or S-RET. - Additional reconnaissance includes probing `/SiteRegister` and `/CommunitiesSelfReg` endpoints to check for self-registration, which could enable broader access. ServiceNow Targets: - The attacker abuses the POST `/api/now/sp/search` endpoint, designed for portal search functionality, to extract data from misconfigured search sources. While defenders can detect automated searches, ServiceNow’s logs do not record the exact search terms used. - Activity has escalated from tens to hundreds of daily requests in some environments. ### Key Observations - The campaign’s infrastructure has remained static since March 2025, unlike previous groups like ShinyHunters, which used multiple IPs. - While some tactics resemble past ShinyHunters attacks (e.g., Aura endpoint abuse), Reco found no direct link between the two. - All observed activity involves guest users, though authenticated access cannot be ruled out. The attacks underscore the risks of misconfigured guest-user permissions in SaaS platforms, where even minor oversights can expose sensitive data to automated theft.
INCIDENT DETAILS -
TYPE
Data Theft
MOTIVATION
Data exfiltration
IMPACT
Data Compromised: Sensitive data exposed (e.g., Accounts, Contacts, Cases)Salesforce Experience CloudServiceNow customer portalsOperational Impact: Data enumeration and theft from exposed objectsIdentity Theft Risk: High (if personally identifiable information was exposed)
DATA BREACH
AccountsContactsCasesOther sensitive recordsNumber Of Records Exposed: Over 560,000 enumeration events recorded for one victimSensitivity Of Data: High (potentially personally identifiable information)Data Exfiltration: YesPersonally Identifiable Information: Possible
JULY 2026
753Before Incident
JUNE 2026
753Before Incident
MAY 2026
753Before Incident
APRIL 2026
753Before Incident
MARCH 2026
753Before Incident
FEBRUARY 2026
753Before Incident
JANUARY 2026
753Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident
OCTOBER 2025
753Before Incident
SEPTEMBER 2025
753Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Contabo ?
?
What was Contabo's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Contabo's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Contabo's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Contabo's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Contabo's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Contabo's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Contabo's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Contabo's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Contabo's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Contabo's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Contabo's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Contabo's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Contabo ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Contabo's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Contabo Cyber Scoring History | Rankiteo