Attackers breached Klue, a market intelligence platform, by abusing a compromised legacy integration credential and planting malicious code that harvested customer OAuth tokens from Klue's integration infrastructure. The stolen tokens were then used to access connected Salesforce environments through the Klue Battlecards app and exfiltrate CRM data via Salesforce REST API queries, with reporting describing automated Python-based collection, burst querying, and use of endpoints such as /services/data/v59.0/query/*. Klue said it detected unauthorized activity on June 12, revoked affected credentials and tokens, removed the malicious code, disabled impacted integrations, engaged CrowdStrike, and notified law enforcement, while Salesforce separately disabled the Klue Battlecards connection and said the incident did not result from a vulnerability in the Salesforce platform itself.
The breach has been linked by Huntress and other responders to the Icarus extortion group, which allegedly sent ransom emails and threatened to leak stolen data on its site. Publicly disclosed victims include Huntress, Recorded Future, Jamf, Tanium, HackerOne, OneTrust, Snyk, Sprout Social, Gong, Insurity, and others, with exposed information generally limited to business CRM records such as contacts, account data, quotes, sales communications, and contract-related details. Affected companies said there was no evidence that core products, internal infrastructure, passwords, payment card data, engineering systems, or customer security telemetry were compromised, but several warned that the stolen contact data could be used in follow-on phishing and social engineering campaigns.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
31 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-13, Microsoft published analysis of campaigns observed from mid-2025 to mid-2026 that used tradecraft overlapping with ShinyHunters to compromise Salesforce customer environments via malicious OAuth apps, supply-chain compromises of integrated vendors including Klue, and abuse of Salesforce Aura guest-user access. Microsoft said the activity abused trusted relationships and configuration weaknesses rather than an inherent Salesforce software vulnerability.
By 2026-06-29, reporting said the number of organizations publicly confirming Salesforce compromise through the Klue breach had risen to 20. This marked a notable escalation in the known downstream impact of the Klue-linked supply chain incident.
On 2026-06-26, Camunda published investigation results regarding the Klue/Salesforce security breach, indicating it was affected by the broader Klue-linked incident. This adds Camunda to the list of publicly identified downstream organizations impacted through the compromised Klue integration.
On 2026-06-26, Deel published a notice describing its impact from the Klue security incident, adding Deel to the list of publicly identified downstream victims affected through Klue-connected systems. This is a new victim disclosure within the broader Klue-linked campaign.
By 2026-06-26, Klue reportedly told customers it had contacted the Icarus extortion group, which then began deleting stolen data from the Klue-linked breach. The same update said no extortion group other than Icarus had publicly claimed possession of the Klue-related data, despite concerns that another actor may have obtained samples.
On 2026-06-25, Link11 published a notice stating that certain CRM data was affected in the third-party security incident involving Klue. This adds Link11 to the list of publicly disclosed downstream organizations impacted through the Klue-connected CRM/Salesforce exposure.
On 2026-06-25, Klue told customers that Icarus said a second unnamed extortion group had obtained some of the stolen data and was now threatening Klue customers directly. Klue assessed that the second group likely had only sample data for a subset of customers rather than the full dataset and advised customers not to pay without proof.
By 2026-06-24, SecurityWeek reported that BeyondTrust was among the organizations impacted by the Klue supply chain incident affecting Salesforce-connected environments. The exposed information was described in line with other victims as business or CRM-related data rather than compromise of core internal systems or products.
By 2026-06-23, LastPass disclosed that attackers accessed customer data in its Salesforce environment after OAuth tokens were stolen in the Klue supply chain attack. LastPass said its core products, infrastructure, and customer vaults were not affected, and that it disabled Klue access, rotated exposed tokens, and notified law enforcement.
By 2026-06-23, Snyk said the Klue incident exposed business data in its Salesforce environment, including customer business contact information and the title and description of a limited subset of support cases. Snyk said support case bodies and its products were not affected, and that it disabled Klue’s Salesforce integration and began an internal review after notification.
By 2026-06-23, Dark Reading reported that the Icarus extortion group had started leaking data on its dark web site after previously setting a deadline for Klue customers to make contact. This marked the transition from extortion threats to actual publication of stolen information from the Klue-linked compromise.
SecurityWeek reported that Icarus threatened to publish the stolen data unless negotiations occurred by 2026-06-22. This marked a public escalation of the extortion campaign following the compromise of Klue-connected Salesforce environments.
By 2026-06-22, at least nine organizations had publicly disclosed impact from the Klue incident, including HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, Tanium, Insurity, Sprout Social, and Gong. Disclosures consistently described the stolen information as Salesforce business or CRM data rather than compromise of core products or internal infrastructure.
On 2026-06-22, Insurity disclosed that after Salesforce notified it of suspicious activity on 2026-06-16, it found CRM data exposure tied to the Klue connected application. Insurity said only a very limited set of active credentials were exposed and rotated or reset them all, while stating its products, cloud environments, and managed infrastructure were not impacted.
On 2026-06-19, reporting said the Icarus extortion group publicly claimed responsibility for the Klue intrusion on its leak site. The claim followed earlier victim extortion emails and tied the broader Salesforce data theft campaign to Icarus rather than older ShinyHunters-branded activity.
On 2026-06-19, HackerOne disclosed that the Klue breach led to unauthorized access and copying of CRM data through Klue's OAuth integration with its Salesforce instance. HackerOne said its products and infrastructure were not impacted and that customer vulnerability data was not stored in the affected CRM environment.
By 2026-06-19, Klue had publicly confirmed that attackers used a compromised legacy credential to obtain OAuth tokens for third-party platforms, including Salesforce, and access data in multiple customers' connected environments. Klue said it revoked affected credentials and tokens, removed unauthorized code, engaged CrowdStrike, and notified law enforcement.
On 2026-06-18, Tines published a notice about the impact of the Klue breach on Tines and its customers, adding Tines to the list of publicly disclosed downstream organizations affected by the Klue-linked incident. This is a new victim disclosure within the broader campaign.
On 2026-06-18, Tanium disclosed that unauthorized access to its Salesforce CRM data occurred through Klue's OAuth integration. Tanium said the incident did not affect its products or cloud infrastructure and was limited to sales account and business contact information.
On 2026-06-18, Jamf disclosed that an unauthorized party accessed data in its Salesforce instance through Klue's integration. Jamf said the incident was confined to Klue's environment and that it found no evidence of lateral movement into its own products or core infrastructure.
On 2026-06-18, Huntress disclosed that its Salesforce data was stolen in a Klue-originated supply chain attack and said the exposed data included business contacts, quotes, sales communications, and competitive reports. Huntress assessed with high confidence that the extortion group Icarus was responsible for the Klue compromise.
In March 2026, financial consulting and advisory firm CFGI was targeted in a pay-or-leak extortion campaign attributed to ShinyHunters. The actor later publicized data it claimed to have obtained, including corporate contact information affecting 243,000 unique email addresses.
On 2026-06-17, OneTrust identified unauthorized activity in its Salesforce environment and linked it to the broader Klue third-party integration incident. OneTrust said the exposure appears limited to CRM-related data accessible through the Klue-Salesforce integration, took containment measures, and began notifying customers believed to be affected.
On 2026-06-17, Recorded Future confirmed that a compromised OAuth token tied to the Salesforce-Klue integration affected elements of its Salesforce account. The company said the exposure appeared limited to business data such as client contact names, email addresses, and potentially some contract information.
On 2026-06-17, Salesforce disabled the Klue Battlecards app connection after detecting unusual activity that may have led to unauthorized access to a subset of customer data. Salesforce said the issue was limited to Klue's integration and did not stem from a vulnerability in Salesforce itself.
On 2026-06-16, Huntress said it received extortion emails after data was stolen through the Klue compromise. Huntress linked the messages to the emerging Icarus group using matched Session Messenger identifiers and related infrastructure.
On 2026-06-13, Klue issued a general customer alert about the incident and suspended or disabled multiple integrations while investigating. Reporting says this included revoking customer OAuth credentials and disrupting connections to Salesforce and other SaaS platforms.
On 2026-06-12, LastPass said it learned that an unauthorized actor used OAuth tokens stolen from Klue to access customer and CRM data in its Salesforce environment. LastPass said the incident was limited to Klue-integrated systems, found no evidence Gong-related data was accessed, and began remediation including token rotation and ending employee access to Klue.
On 2026-06-12, Klue detected unusual or unauthorized activity in its environment tied to the compromised integration layer. Klue began containment by revoking affected credentials and tokens, removing unauthorized code, and disabling impacted integrations.
On 2026-06-11, attackers used a compromised dormant or legacy Klue credential tied to an integration service or prototype to access Klue's backend infrastructure. They then inserted malicious code to harvest customer OAuth tokens used by connected third-party services, especially Salesforce.
Gainsight published an update supporting customers and the community regarding a recent security advisory, indicating it was affected by the broader incident. This adds Gainsight to the list of publicly identified downstream organizations impacted through the compromised third-party integration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
50 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcethehackernews.com
Open sourcemalware.news
Open sourcemicrosoft.com
Open sourcegong.io
Open sourcehelpnetsecurity.com
Open sourcemalware.news
Open sourcesecurity.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.