Klue OAuth breach let Icarus extortion group steal Salesforce customer data from multiple organizations

Klue says attackers abused its Salesforce-connected Battlecards app to steal CRM data from multiple customer organizations, and victims are now receiving extortion demands from the Icarus group. According to ReliaQuest, Huntress, and BleepingComputer, the attackers used compromised Klue service accounts and associated OAuth tokens to access customer Salesforce instances, enumerate objects through Salesforce REST API endpoints, and exfiltrate records over hours; Salesforce has disabled the Klue Battlecards integration while the incident is investigated.
Why it matters: Organizations that connected Klue Battlecards to Salesforce may have had sensitive sales, customer, or internal business data stolen without a malware outbreak or password spray. Affected teams should urgently review Salesforce OAuth-connected apps and token activity, check for unusual API queries, and prepare for extortion emails tied to this campaign.

Sources

Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths
info@thehackernews.com (The Hacker News) 2026.07.14 79% relevant
This article adds broader campaign context from Microsoft, saying ShinyHunters-linked actors spent about a year stealing data from Salesforce through three intrusion paths, which helps explain how Salesforce-connected extortion incidents like the Klue breach fit into a wider pattern.
More Klue Breach Victims Identified as Hackers Get Hacked
Ionut Arghire 2026.06.26 96% relevant
This article directly updates the same Klue-Salesforce supply-chain incident, adding that roughly two dozen customers have now disclosed impact, naming additional victims such as AlertMedia, Blackbaud, Camunda, Cresta, Deel, Lucanet, Link11, and Tines. It also adds scope claims of 195 affected Klue customers, notes Salesforce and Gong disabled the integration, and reports Klue told customers that Icarus was itself hacked and sample stolen data may now be in another actor’s hands.
BeyondTrust, LastPass Impacted by Klue-Salesforce Incident
Ionut Arghire 2026.06.24 98% relevant
This article directly updates the same Klue-Salesforce breach by adding newly disclosed affected organizations including LastPass, BeyondTrust, 8x8, and Pendo, and reiterates that Icarus used a compromised legacy credential to mint OAuth tokens and exfiltrate CRM data from connected Salesforce instances.
LastPass confirms data breach in Klue supply chain attack
Bill Toulas 2026.06.23 97% relevant
This is a direct update on the same Klue OAuth supply-chain incident, adding that LastPass has confirmed impact, describing the Salesforce data types exposed, stating customer vaults and core infrastructure were not affected, and listing mitigations such as token rotation and Klue access revocation.
Security shops among the 'hundreds' of Klue hack victims
2026.06.22 94% relevant
This article is a direct update on the same Klue breach, adding that Huntress and several other security and software vendors disclosed they were affected, that Klue says the intrusion began with a compromised legacy integration credential on June 11, and that the attacker used stolen OAuth tokens to access connected Salesforce customer environments.
More Cybersecurity Firms Disclose Impact From Klue Hack
Ionut Arghire 2026.06.22 96% relevant
This article directly updates the same Klue breach by adding more confirmed affected organizations, stating Klue’s account of the intrusion path via compromised legacy credentials and stolen OAuth tokens, noting Salesforce and Gong disabled integrations, and reporting that Icarus has claimed the attack on its leak site and set a publication deadline.
Klue OAuth breach victim list grows as Icarus hackers claim attack
Lawrence Abrams 2026.06.19 98% relevant
This article directly updates the same Klue breach by adding Klue's public confirmation, the initial intrusion vector of a compromised legacy integration credential, Icarus's public claim on its leak site, and additional named victims including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity.
Cybersecurity Firms Impacted by Klue Supply Chain Attack
Ionut Arghire 2026.06.19 98% relevant
This is a direct update on the same Klue incident, adding confirmed affected customers (Huntress and Recorded Future), details on the stolen Salesforce data fields, Salesforce's disabling of the Klue Battlecards app, ReliaQuest observations on API-based exfiltration, and Huntress's attribution of the attack to the Icarus extortion group via 'Mr Brean' communications.
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
info@thehackernews.com (The Hacker News) 2026.06.19 98% relevant
This is the same underlying event and adds that Salesforce itself disabled the Klue app integration in response to the OAuth token abuse that exposed customer data across multiple organizations.
Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
Lawrence Abrams 2026.06.18 100% relevant
This article establishes the specific underlying event: a Klue OAuth compromise used by the Icarus extortion group to access and steal data from multiple Salesforce customer environments.
← Back to all stories