Klue says attackers abused its Salesforce-connected Battlecards app to steal CRM data from multiple customer organizations, and victims are now receiving extortion demands from the Icarus group. According to ReliaQuest, Huntress, and BleepingComputer, the attackers used compromised Klue service accounts and associated OAuth tokens to access customer Salesforce instances, enumerate objects through Salesforce REST API endpoints, and exfiltrate records over hours; Salesforce has disabled the Klue Battlecards integration while the incident is investigated.
info@thehackernews.com (The Hacker News)
2026.07.14
79% relevant
This article adds broader campaign context from Microsoft, saying ShinyHunters-linked actors spent about a year stealing data from Salesforce through three intrusion paths, which helps explain how Salesforce-connected extortion incidents like the Klue breach fit into a wider pattern.
Ionut Arghire
2026.06.26
96% relevant
This article directly updates the same Klue-Salesforce supply-chain incident, adding that roughly two dozen customers have now disclosed impact, naming additional victims such as AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines. It also adds scope claims of 195 affected Klue customers, notes Salesforce and Gong disabled the integration, and reports Klue told customers that Icarus was itself hacked and sample stolen data may now be in another actor’s hands.
Ionut Arghire
2026.06.24
98% relevant
This article directly updates the same Klue-Salesforce breach by adding newly disclosed affected organizations including LastPass, BeyondTrust, 8x8, and Pendo, and reiterates that Icarus used a compromised legacy credential to mint OAuth tokens and exfiltrate CRM data from connected Salesforce instances.
Bill Toulas
2026.06.23
97% relevant
This is a direct update on the same Klue OAuth supply-chain incident, adding that LastPass has confirmed impact, describing the Salesforce data types exposed, stating customer vaults and core infrastructure were not affected, and listing mitigations such as token rotation and Klue access revocation.
2026.06.22
94% relevant
This article is a direct update on the same Klue breach, adding that Huntress and several other security and software vendors disclosed they were affected, that Klue says the intrusion began with a compromised legacy integration credential on June 11, and that the attacker used stolen OAuth tokens to access connected Salesforce customer environments.
Ionut Arghire
2026.06.22
96% relevant
This article directly updates the same Klue breach by adding more confirmed affected organizations, stating Klue’s account of the intrusion path via compromised legacy credentials and stolen OAuth tokens, noting Salesforce and Gong disabled integrations, and reporting that Icarus has claimed the attack on its leak site and set a publication deadline.
Lawrence Abrams
2026.06.19
98% relevant
This article directly updates the same Klue breach by adding Klue's public confirmation, the initial intrusion vector of a compromised legacy integration credential, Icarus's public claim on its leak site, and additional named victims including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity.
Ionut Arghire
2026.06.19
98% relevant
This is a direct update on the same Klue incident, adding confirmed affected customers (Huntress and Recorded Future), details on the stolen Salesforce data fields, Salesforce's disabling of the Klue Battlecards app, ReliaQuest observations on API-based exfiltration, and Huntress's attribution of the attack to the Icarus extortion group via 'Mr Brean' communications.
info@thehackernews.com (The Hacker News)
2026.06.19
98% relevant
This is the same underlying event and adds that Salesforce itself disabled the Klue app integration in response to the OAuth token abuse that exposed customer data across multiple organizations.
Lawrence Abrams
2026.06.18
100% relevant
This article establishes the specific underlying event: a Klue OAuth compromise used by the Icarus extortion group to access and steal data from multiple Salesforce customer environments.