Attackers breached market intelligence vendor Klue and used a compromised legacy credential tied to an old integration service to implant malicious code, harvest customer OAuth tokens, and access connected Salesforce environments through the Klue Battlecards app. Incident responders and affected companies said the attackers then used legitimate Salesforce REST API access to enumerate objects and exfiltrate CRM data over many hours, including business contacts, account records, quotes, sales communications, support case metadata, and related commercial information. Salesforce disabled the Klue app connection during the investigation and stressed the incident did not result from a vulnerability in the Salesforce platform itself, while Klue revoked credentials and tokens, disabled multiple integrations, engaged CrowdStrike, and notified law enforcement.
The campaign has been widely attributed to the Icarus extortion group, which allegedly sent ransom demands and threatened to leak stolen data, though some reporting noted tradecraft overlaps with ShinyHunters-style Salesforce OAuth abuse. Publicly disclosed victims grew from early reports involving Huntress, Recorded Future, Jamf, Tanium, Sprout Social, Gong, HackerOne, Snyk, OneTrust, and Insurity to later confirmations from LastPass, BeyondTrust, and others, with some reports putting the total affected customer count far higher. Most impacted organizations said the exposure was largely confined to CRM and business data in Salesforce or connected apps, with no evidence that core products, internal infrastructure, password vaults, payment data, or engineering systems were compromised.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
41 events from the most recent confirmed update back to the earliest known activity.
On July 13, 2026, Microsoft published research describing three Salesforce attack paths observed from mid-2025 to mid-2026, including vishing-based app consent abuse, vendor integration compromise, and guest-access abuse.
By June 26, 2026, SecurityWeek reported that roughly two dozen Klue customers had publicly confirmed compromise, including AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines.
In the same June 25, 2026 customer update, Klue said Icarus reported that a second unnamed group had obtained sample data for a subset of customers and was attempting separate extortion.
TechCrunch reported on June 25, 2026 that Klue told customers it was communicating with Icarus and believed the group was taking steps to delete stolen customer data.
By June 24, 2026, SecurityWeek reported additional impacted organizations including BeyondTrust, 8x8, and Pendo, pushing the public victim count to roughly 15.
TechCrunch reported on June 23, 2026 that Klue said the compromised credential used in the attack originated from a limited 2022 pilot with a third party and had not been revoked.
On June 23, 2026, LastPass said attackers used OAuth tokens stolen from Klue to access customer data in its Salesforce environment, including contact details, support case information, and sales-related records.
Cyber Security News reported that Klue CEO Jason Smith publicly acknowledged the breach on June 22, 2026 and described it as a deliberate criminal act.
Insurity said on June 22, 2026 that its review found a limited set of active credentials exposed in CRM data and that it proactively rotated or reset them.
Snyk said on June 22, 2026 that an unauthorized party accessed business data in its Salesforce environment through Klue, including customer contact information and limited support case metadata.
SecurityWeek and Dark Reading reported that Icarus threatened to publish stolen data on June 22, 2026 unless Klue or affected customers entered negotiations.
By June 22, 2026, reporting and company disclosures had identified a growing list of affected organizations including HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, Tanium, Insurity, Sprout Social, and Gong.
Klue publicly confirmed on June 19, 2026 that attackers used a compromised legacy credential to obtain OAuth tokens for third-party platforms and access data in connected customer environments.
On June 19, 2026, Icarus claimed responsibility for the Klue-related intrusion and threatened to publish stolen customer Salesforce data unless negotiations occurred.
Gong said on June 19, 2026 that a subset of customers using the Klue integration may have had internal licensed user data such as names, titles, and email addresses accessed.
HackerOne disclosed on June 19, 2026 that CRM data was accessed and copied through Klue's OAuth integration with its Salesforce instance, while saying its products and infrastructure were unaffected.
Tanium said on June 18, 2026 that an unauthorized party accessed CRM data in its Salesforce environment through Klue, including sales account and business contact information.
Jamf disclosed on June 18, 2026 that a third party accessed data in its Salesforce instance through Klue's integration, while stating its products and core services were unaffected.
Recorded Future published its disclosure on June 18, 2026, saying the impact was limited to business data in Salesforce and that its core platform and internal systems were not compromised.
On June 18, 2026, Huntress disclosed that Klue's compromise led to theft of CRM data from its Salesforce environment, including business contacts, price quotes, sales communications, and competitive reports.
OneTrust said it identified unauthorized activity in its Salesforce environment on June 17, 2026 and linked it to the broader Klue third-party integration incident.
Recorded Future said it confirmed on June 17, 2026 that elements of its Salesforce account were affected through a compromised OAuth token tied to the Salesforce-Klue integration.
Salesforce published a security advisory on June 17, 2026 saying it had disabled the Klue Battlecards app connection after detecting unusual activity that may have exposed a subset of customer data.
Insurity said Salesforce notified it on June 16, 2026 about suspicious activity involving the Klue connected application used with its Salesforce environment.
On June 16, 2026, Huntress employees began receiving extortion emails with the subject line 'top secret email' stating that Salesforce data had been downloaded and demanding contact via Session within 48 hours.
Klue sent a general alert to customers on June 13, 2026, warning of the incident but not initially specifying which customers were impacted.
Sprout Social said unauthorized access to its Salesforce CRM through the Klue integration occurred between June 11 and June 12, 2026, exposing business contact and account-related CRM data.
On June 12, 2026, Klue disabled attacker remote access, removed the malicious code, and began revoking affected OAuth credentials and integrations to contain the breach.
Klue said it identified unauthorized activity affecting part of its integration infrastructure on June 12, 2026 after observing unusual connections tied to attacker-controlled systems.
ReliaQuest and Huntress reported that the attackers used stolen OAuth tokens and automated Python scripts to query Salesforce REST APIs, enumerate objects, and exfiltrate CRM data from multiple customer environments over extended periods.
After gaining access, the attackers inserted malicious code into Klue infrastructure to harvest customer OAuth tokens used for integrations with Salesforce and other services.
Huntress, Datadog, and others said attackers gained access to Klue's backend on June 11, 2026 using a long-unused but still-active credential tied to an old integration prototype.
Microsoft said in July 2026 that the June 2026 Klue incident involved Storm-3138, which used credentials from the compromise to access Salesforce customer instances and exfiltrate data.
Multiple sources said Icarus emerged in April 2026 and began operating a leak site and extortion infrastructure before the Klue incident became public.
After the CFGI intrusion, ShinyHunters publicized data it claimed to have obtained, including 243,000 unique email addresses plus names, phone numbers, and physical addresses.
Have I Been Pwned reported that financial consulting firm CFGI was targeted in a ShinyHunters pay-or-leak extortion campaign in March 2026.
Cato Networks reported that multiple high-profile administrators tied to the broader ShinyHunters ecosystem were arrested in France in 2025.
Cato Networks said that by 2025 the ShinyHunters identity had expanded through the Scattered LAPSUS$ Hunters federation, reflecting an organizational evolution of the brand.
Klue later said the credential abused in the 2026 breach dated back to a limited 2022 pilot and remained active after the project ended. That legacy credential became the initial access point used in the later intrusion.
Cato Networks said ShinyHunters first established its reputation in 2020 through high-volume database brokerage, providing background for later campaigns tied to the brand.
As part of its response to the Klue breach, the company said it notified law enforcement, opened an internal investigation, and engaged CrowdStrike to support forensic analysis and review security controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
cert.gov.az
Open sourcecsoonline.com
Open sourcecybersecuritynews.com
Open sourcethehackernews.com
Open sourcesecurityweek.com
Open sourcethehackernews.com
Open sourceklue.com
Open sourcesecurity.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.