Klue OAuth Breach Linked to Icarus Salesforce Data Theft Attacks

Klue’s OAuth-based Battlecards integration was exploited by the Icarus extortion group to steal Salesforce CRM data from multiple organizations. Attackers used compromised OAuth tokens to query Salesforce APIs after initial reconnaissance, exfiltrating data over several hours before Salesforce disabled the Klue integration. ReliaQuest and Huntress confirm the incident, noting stolen data includes CRM records, contacts, quotes, and competitive intelligence; Klue has since cut connections to Salesforce and other apps. Organizations are advised to revoke and rotate OAuth tokens, terminate active sessions, and review Salesforce logs for unusual API activity.

TechLogHub
June 18, 2026
5 min read
0 views

Share Article

Klue OAuth Breach Linked to Icarus Salesforce Data Theft Attacks

KLUE OAUTH BREACH LINKED TO 'ICARUS' SALESFORCE DATA THEFT ATTACKS

IntroductionA security incident involving the market intelligence platform Klue has surfaced, tying an OAuth breach to a new extortion operation known as “Icarus.” The breach exposed Salesforce CRM data across multiple organizations and has prompted investigations from cybersecurity firms and responses from Salesforce. The event marks another instance where third-party integrations with enterprise systems become attack vectors for data theft and extortion.

What happened

  • Attack vector: An OAuth breach during a Klue Battlecards integration allowed threat actors to access customer Salesforce instances.
  • Threat actor: A group identified as Icarus, a relatively new extortion operation, is linked to the campaign. Icarus began contacting Klue customers with extortion demands.
  • Extortion model: Victims are being contacted with ransom notes and directed to communicators associated with Icarus through various channels, including a data leak site and email aliases.

The players involved

  • Klue: A market intelligence platform whose Battlecards integration connected to external services.
  • Salesforce: The CRM platform affected by unauthorized access via OAuth tokens stolen through the integration.
  • Icarus: The extortion group implicated in the campaign, delivering ransom notes and leveraging a data leak site.
  • ReliaQuest and Huntress: Cybersecurity firms that published analyses confirming and detailing aspects of the incident.
  • ShinyHunters (for context): A previously active group associated with similar data theft patterns, though not attributed to this particular attack.

How the breach unfolded

  • Initial access: Attackers gained access to Klue Battlecards integration service accounts and used OAuth tokens tied to customer Salesforce instances.
  • Reconnaissance: The attackers used OAuth tokens to query Salesforce via REST API, beginning with inventory-like reconnaissance of Salesforce objects.
  • Data exfiltration: After mapping valuable objects, the attackers intensified data extraction, performing hundreds to thousands of API queries in bursts within short windows.
  • Targeted timing: The activity ranged from slow, stealthy collection to bursts intended to accelerate exfiltration, indicating potential time pressure or shifting focus to specific records.
  • End result: CRM-related data, including business contacts, sales communications, price quotes, competitive intelligence reports, and account data, were accessed or exfiltrated.

Evidence and findings

  • Observations by ReliaQuest:
  • Attackers used compromised Klue integration credentials to issue OAuth tokens and query Salesforce environments over an extended period.
  • The activity included an initial slow pull followed by rapid, high-volume queries, suggesting a transition from stealth to speed.
  • One environment saw almost a thousand queries within a 15-minute window.
  • Observations by Huntress:
  • The breach impacted Klue customers via a similar extortion channel, with shared indicators across communications.
  • Session IDs in later extortion emails matched those listed on Icarus’ data leak site, strengthening the link to Icarus.
  • Klue reportedly disabled multiple integrations (Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, Slack) as part of incident response.
  • Data scope:
  • Stolen data reportedly includes CRM-related materials such as business contacts, sales communications, price quotes, competitive intelligence, and account data.
  • There was no evidence that threat intelligence, customer telemetry, passwords, payment card data, or engineering systems were compromised.
  • Technical indicators:
  • IP addresses associated with the attack were identified and shared by investigators as 138.226.246.94, 212.86.125.24, 213.111.148.90, and 94.154.32.160.

The Icarus extortion campaign

  • Extortion communications: Icarus used email aliases and a Session Messenger ID to contact victims, with ransom notes indicating a broader list of targets.
  • Data leak site: Icarus operates a data leak site where messages and victim listings are posted, signaling a public-facing extortion component.
  • Timeline hints: Icarus appears to have launched in April 2026, with initial postings listing victims and expanding as additional targets were identified.

Salesforce response

  • Immediate action: Salesforce disabled the Klue Battlecards integration within the Salesforce ecosystem as part of the ongoing investigation.
  • Scope of impact: The lockout affected customers using the Battlecards app to connect Klue with Salesforce, temporarily severing that integration until a broader resolution is achieved.

Current status and indicators

  • Incident status: Investigations are ongoing as multiple parties review access vectors, compromised tokens, and potential recovery options.
  • Victim signals: Several Klue customers reported data exposure related to Salesforce-connected workflows; some partners and services connected to Klue may have also been affected.
  • For organizations using Klue integrations:
  • Review Salesforce and related SaaS logs for activity from known attack IPs.
  • Revoke and rotate OAuth tokens associated with Klue and connected apps.
  • Terminate active sessions that may have been compromised.
  • Review Salesforce logs for unusual API activity to identify potential exfiltration patterns.

Key takeaways from the investigation

  • Third-party integrations remain a critical risk: The attack underscores how OAuth-based connections can become a vector for data theft across enterprise platforms.
  • Verification beyond attribution matters: While Icarus is identified as the extortion actor in this campaign, direct attribution can be challenging; corroborating evidence from multiple researchers is essential to forming a confident attribution.
  • Extortion operations are evolving: The emergence of a dedicated data leak site and extortion correspondence signals a maturing approach to monetizing access through public leakage and organized pressure on victims.

Data exposure and what’s known about victims

  • What was accessed: CRM-related data, including customer contacts, sales communications, quotes, competitive intelligence reports, and account details.
  • What remains uncertain: The total number of affected organizations and the full extent of data exfiltrated across all Klue customers; ongoing investigations aim to quantify scope more precisely.

Context and related developments

  • Prior patterns: The attack shares similarities with earlier Salesforce data theft campaigns tied to third-party integrations and extortion efforts, though investigators emphasize that this incident appears distinct in its Icarus affiliation.
  • Industry implications: The incident highlights the need for stronger controls around OAuth token management, tighter monitoring of API usage, and robust checks on third-party integrations in enterprise cloud environments.

ConclusionThe Klue OAuth breach tied to the Icarus extortion operation marks a notable case in enterprise security, illustrating how compromise of a single integration can cascade into widespread data exposure across multiple organizations. As investigations continue, organizations relying on Klue Battlecards and Salesforce integrations should monitor for unusual API activity and recall or rotate credentials tied to connected services. The evolving threat landscape demonstrated by Icarus also emphasizes the ongoing risk posed by extortion groups that leverage public-facing data leaks and targeted phishing-like communications to pressure victims.

Stay Updated

Get the next deep dive in your inbox

Subscribe for product analysis, engineering explainers, and practical guides published on TechLogHub.

See what launched this week

One email a week: new and trending developer tools, fresh comparisons, and what shipped. Unsubscribe in one click.

Klue OAuth Breach Linked to Icarus Salesforce Data Theft Attacks | TechLogHub