Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
third-party-vendor-breachdata-exfiltration-methodidentity-authentication-vulnerabilityunderground-data-leak

Klue OAuth Supply-Chain Breach Exposed Salesforce Data Across Multiple Customers

Updated 4h agoFirst seen Jun 18, 202633 sources

Attackers breached Klue, a market intelligence platform, by abusing a compromised legacy integration credential and planting malicious code that harvested customer OAuth tokens from Klue's integration infrastructure. The stolen tokens were then used to access connected Salesforce environments through the Klue Battlecards app and exfiltrate CRM data via Salesforce REST API queries, with reporting describing automated Python-based collection, burst querying, and use of endpoints such as /services/data/v59.0/query/*. Klue said it detected unauthorized activity on June 12, revoked affected credentials and tokens, removed the malicious code, disabled impacted integrations, engaged CrowdStrike, and notified law enforcement, while Salesforce separately disabled the Klue Battlecards connection and said the incident did not result from a vulnerability in the Salesforce platform itself.

The breach has been linked by Huntress and other responders to the Icarus extortion group, which allegedly sent ransom emails and threatened to leak stolen data on its site. Publicly disclosed victims include Huntress, Recorded Future, Jamf, Tanium, HackerOne, OneTrust, Snyk, Sprout Social, Gong, Insurity, and others, with exposed information generally limited to business CRM records such as contacts, account data, quotes, sales communications, and contract-related details. Affected companies said there was no evidence that core products, internal infrastructure, passwords, payment card data, engineering systems, or customer security telemetry were compromised, but several warned that the stolen contact data could be used in follow-on phishing and social engineering campaigns.

Share:
Klue OAuth Supply-Chain Breach Exposed Salesforce Data Across Multiple Customers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

15 events from the most recent confirmed update back to the earliest known activity.

15 EVENTS
Jun 22, 20261d ago

Icarus sets June 22 deadline to publish stolen data

SecurityWeek reported that Icarus threatened to publish the stolen data unless negotiations occurred by 2026-06-22. This marked a public escalation of the extortion campaign following the compromise of Klue-connected Salesforce environments.

More Cybersecurity Firms Disclose Impact From Klue Hack - SecurityWeek

More victims publicly disclose impact from Klue breach

By 2026-06-22, at least nine organizations had publicly disclosed impact from the Klue incident, including HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, Tanium, Insurity, Sprout Social, and Gong. Disclosures consistently described the stolen information as Salesforce business or CRM data rather than compromise of core products or internal infrastructure.

More Cybersecurity Firms Disclose Impact From Klue Hack - SecurityWeek
Jun 19, 20264d ago

Icarus publicly claims the Klue attack on leak site

On 2026-06-19, reporting said the Icarus extortion group publicly claimed responsibility for the Klue intrusion on its leak site. The claim followed earlier victim extortion emails and tied the broader Salesforce data theft campaign to Icarus rather than older ShinyHunters-branded activity.

Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data

HackerOne discloses copied Salesforce CRM data

On 2026-06-19, HackerOne disclosed that the Klue breach led to unauthorized access and copying of CRM data through Klue's OAuth integration with its Salesforce instance. HackerOne said its products and infrastructure were not impacted and that customer vulnerability data was not stored in the affected CRM environment.

Security Advisory: HackerOne's Response to the Klue Breach | HackerOne

Klue publicly confirms security incident

By 2026-06-19, Klue had publicly confirmed that attackers used a compromised legacy credential to obtain OAuth tokens for third-party platforms, including Salesforce, and access data in multiple customers' connected environments. Klue said it revoked affected credentials and tokens, removed unauthorized code, engaged CrowdStrike, and notified law enforcement.

Klue OAuth breach victim list grows as Icarus hackers claim attack
Jun 18, 20265d ago

Tanium discloses CRM data exposure via Klue

On 2026-06-18, Tanium disclosed that unauthorized access to its Salesforce CRM data occurred through Klue's OAuth integration. Tanium said the incident did not affect its products or cloud infrastructure and was limited to sales account and business contact information.

Security Update: Tanium’s Response to the Klue Breach that Allowed Data Exfiltration from Salesforce | Tanium

Jamf discloses unauthorized access to Salesforce data

On 2026-06-18, Jamf disclosed that an unauthorized party accessed data in its Salesforce instance through Klue's integration. Jamf said the incident was confined to Klue's environment and that it found no evidence of lateral movement into its own products or core infrastructure.

Klue Third-Party Cybersecurity Incident

Huntress publicly discloses impact and attributes attack to Icarus

On 2026-06-18, Huntress disclosed that its Salesforce data was stolen in a Klue-originated supply chain attack and said the exposed data included business contacts, quotes, sales communications, and competitive reports. Huntress assessed with high confidence that the extortion group Icarus was responsible for the Klue compromise.

Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress | Huntress

CFGI targeted in ShinyHunters extortion campaign

In March 2026, financial consulting and advisory firm CFGI was targeted in a pay-or-leak extortion campaign attributed to ShinyHunters. The actor later publicized data it claimed to have obtained, including corporate contact information affecting 243,000 unique email addresses.

Have I Been Pwned: CFGI Data Breach
Jun 17, 20266d ago

Recorded Future confirms Salesforce impact

On 2026-06-17, Recorded Future confirmed that a compromised OAuth token tied to the Salesforce-Klue integration affected elements of its Salesforce account. The company said the exposure appeared limited to business data such as client contact names, email addresses, and potentially some contract information.

The Klue Security Incident and Its Impact on Recorded Future - Malware Analysis - Malware Analysis, News and Indicators

Salesforce disables Klue Battlecards connection

On 2026-06-17, Salesforce disabled the Klue Battlecards app connection after detecting unusual activity that may have led to unauthorized access to a subset of customer data. Salesforce said the issue was limited to Klue's integration and did not stem from a vulnerability in Salesforce itself.

Trust Status
Jun 16, 20267d ago

Huntress receives extortion emails tied to Icarus

On 2026-06-16, Huntress said it received extortion emails after data was stolen through the Klue compromise. Huntress linked the messages to the emerging Icarus group using matched Session Messenger identifiers and related infrastructure.

Klue breach lead to Salesforce data theft, Huntress affected - Help Net Security
Jun 13, 202610d ago

Klue issues customer alert and disables integrations

On 2026-06-13, Klue issued a general customer alert about the incident and suspended or disabled multiple integrations while investigating. Reporting says this included revoking customer OAuth credentials and disrupting connections to Salesforce and other SaaS platforms.

Cybercrime Breaches Klue: Salesforce Data Impacted for Many Victims, including Huntress | Huntress
Jun 12, 202611d ago

Klue detects unauthorized activity and begins containment

On 2026-06-12, Klue detected unusual or unauthorized activity in its environment tied to the compromised integration layer. Klue began containment by revoking affected credentials and tokens, removing unauthorized code, and disabling impacted integrations.

The Klue Security Incident and Its Impact on Recorded Future - Malware Analysis - Malware Analysis, News and Indicators
Jun 11, 202612d ago

Attackers compromise Klue backend using legacy credential

On 2026-06-11, attackers used a compromised dormant or legacy Klue credential tied to an integration service or prototype to access Klue's backend infrastructure. They then inserted malicious code to harvest customer OAuth tokens used by connected third-party services, especially Salesforce.

Attackers Steal Salesforce Data From Klue Battlecards Users
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

77 LINKEDOpen in app
Affected products
8 linked
SalesforceHubspotGoogle DriveZoomSharepointAmazon Web ServicesJamfMicrosoft 365
Organizations
43 linked
SalesforceKlueHuntressReliaQuestGongRecorded FutureTaniumJamfSprout SocialInsurityHackerOneCrowdStrikeSnykOneTrustHubspotGoogleSalesloftZoom CommunicationsGainsightSlack TechnologiesMicrosoft CorporationClariDriftChorus.aiBleepingComputerSnowflakeGlobal Retail BrandsTanstackAmazon Web ServicesTechCrunchCato NetworksDatadogDark ReadingOpenaiVercelGong.ioKudelski SecurityZoomInfoGoFileCFGIBaccaratHouseRobin's Kitchen
Breaches
18 linked
KLUE-2026-06HUNTRESS-2026-06RECORDEDFUTURE-2026-06JAMF-2026-06TANIUM-2026-06GONG-2026-06SPROUTSOCIAL-2026-06INSURITY-2026-06HACKERONE-2026-06SNYK-2026-06ONETRUST-2026-06SALESFORCE-2026-06CFGI-2026-06GLOBALRETAILBRANDS-2026-06SALESFORCECUSTOMERS-2026-06RELIAQUEST-2026-06KUDELSKISECURITY-2026-06KUDELSKISECURITY-2026-06
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.