Klue OAuth breach victim list grows as Icarus hackers claim attack
Klue confirms a security incident where OAuth tokens used to connect to Salesforce were stolen, exposing data in several customer Salesforce environments. The breach, linked to the Icarus extortion group, originated from a compromised legacy credential and was detected on June 12; Klue revoked tokens, disabled affected integrations, and engaged CrowdStrike. The company says its own platform data was not affected, but data from third-party integrations was exfiltrated from multiple customers, including Sprout Social, Jamf, Gong, Tanium, Recorded Future, and Insurity. Icarus has publicly claimed responsibility and issued extortion-style demands via its data-leak site and Session Messenger; customers are urged to stay vigilant for follow-on phishing attempts.

Klue OAuth Breach: Victim List Grows as Icarus Hackers Claim Attack
Incident OverviewThe security incident involving Klue, a market intelligence platform, has expanded beyond initial disclosures as the Icarus extortion group publicly claimed responsibility. The breach centers on stolen OAuth tokens used to connect Klue’s systems with customer environments, notably Salesforce CRM instances. Investigations conducted by third parties indicate that attackers abused compromised Klue integrations to gain access to Salesforce data across multiple organizations. Klue has stated that the breach affected third-party integrations and not content stored directly within the Klue platform.
What Happened (Timeline of Key Events)
- June 12, 2026: Klue detects unauthorized activity impacting a portion of its integration infrastructure. The company begins a coordinated response with cybersecurity experts, works to understand the incident, and to restore affected connections.
- Post-incident findings: Investigators determine that the attacker gained access through a compromised legacy credential tied to an integration service. With that access, the attacker obtained OAuth tokens used to connect Klue with third-party platforms, including Salesforce, enabling access to data in several customer environments.
- Immediate containment steps: Klue revokes affected credentials and tokens, removes unauthorized code, disables impacted integrations, and launches a formal investigation. Law enforcement is notified, and CrowdStrike is engaged to assist with the response.
- External investigations and findings: ReliaQuest reports that attackers used stolen OAuth credentials associated with Klue’s integrations to query Salesforce’s API over extended periods, facilitating data exfiltration. Huntress confirms that its own Salesforce environment was affected and that stolen data included business contacts, sales communications, pricing information, and other records.
- Public attribution: After earlier connections by industry observers, the Icarus threat group publicly claims responsibility for the Klue breach on its data leak site and via extortion communications.
How Access Was Gained and What Was Exposed
- Method of access: A compromised legacy credential associated with Klue’s integration service provided a foothold. The attacker leveraged this to obtain OAuth tokens that authorized connections to third-party platforms.
- Targeted data: The primary focus was data within connected Salesforce environments. Attack activity included using Python-based scripts and OAuth tokens to query Salesforce APIs for an extended period, enabling broad data theft.
- Scope of impact: Klue asserts there is no evidence that customer content stored directly within the Klue platform was impacted. The incident is described as limited to third-party integrations, with the most significant risk centered on the exposed Salesforce data within affected customer environments.
Affected Organizations and Data Exposed
- Confirmed victims and affected environments include multiple customers whose Salesforce data was accessed through Klue integrations.
- Specific data categories reported as compromised include business contacts, sales communications, pricing information, and related records.
- Several organizations have disclosed that the breach did not affect Klue’s platform core, infrastructure, payment data, or internal systems beyond the compromised integrations.
- The breadth of victims has expanded beyond Klue’s direct customers, with other parties publicly naming additional organizations that faced data exposure through the same attack chain.
Public Claims and Attribution: Icarus
- Icarus data leak site claims responsibility for the Klue breach and notes that a number of Salesforce instances belonging to Klue’s partners were exfiltrated.
- The extortion narrative included instructions for contacting Icarus via the Session messaging platform to prevent leakage of stolen data, reflecting a typical ransom-driven tactic.
- Subsequent reporting from cybersecurity researchers and researchers’ disclosures linked the Icarus operation to the Klue incident, including the use of Session Messenger IDs in extortion communications and the data leak site.
Victim Roll Call: Additional Notable Organizations
- Beyond Klue’s direct customers, several entities have publicly acknowledged being affected by the incident, with references to exfiltration from Salesforce instances tied to partnerships or integrations associated with Klue.
- Reported by industry observers and security firms, these victims include organizations across various sectors that rely on Salesforce for CRM functionality.
- The common thread among these victims is the exposure of Salesforce data via compromised integration tokens rather than a breach of the organizations’ core platforms.
Implications for Connected Environments and Data Handling
- Trust in third-party integrations: The incident underscores the risk posed by integrations that rely on OAuth tokens and legacy credentials. Even if the primary platform remains secure, compromised tokens can expose connected services.
- Extortion and follow-on campaigns: The data exposed as part of the breach has the potential to fuel phishing, social engineering, and further extortion attempts against affected organizations and their clients.
- Data scope and containment: While the breach affected Salesforce data accessible through Klue integrations, the broader impact on Klue’s own systems appears limited according to public statements. The distinction between data stored in the Klue platform and data accessed via integrations is a key factor in assessing overall exposure.
Public Disclosures and Related Coverage
- Coverage and analysis by cybersecurity outlets have traced the attack vectors to compromised integration credentials and the abuse of OAuth tokens used to access Salesforce environments.
- Observations from ReliaQuest and Huntress provide technical details on how tokens were generated, used, and exploited for data exfiltration, including long-running API queries and scripting.
- Additional victims and updates have been reported by Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity, highlighting a broader set of affected Salesforce instances tied to Klue’s ecosystem.
Current Status and Next Steps for Stakeholders
- Ongoing investigations: Klue continues to work with cybersecurity experts to fully understand the breach vector and to reinforce defenses around third-party integrations.
- Remediation efforts: The organization has taken containment measures by revoking compromised credentials, disabling affected integrations, and engaging incident response partners.
- Public safety posture: Stakeholders of affected organizations are encouraged to review their Salesforce-access controls and monitor for unusual activity in CRM data and related channels, given the potential for phishing and social engineering arising from stolen contact information and credentials.
Notes on Data Security Context
- The incident highlights the risk inherent in legacy credentials and the importance of securing integration points that span multiple platforms.
- The role of external security firms in incident response and the value of rapid credential revocation and platform isolation are reflected in the containment measures described by Klue and corroborated by third-party researchers.
Summary of Key Points
- A compromised legacy credential allowed an attacker to obtain OAuth tokens used to connect Klue to Salesforce, enabling extensive data access across multiple customer environments.
- The breach affected third-party integrations rather than Klue’s core platform data, with most impacted data residing in connected Salesforce instances.
- The Icarus extortion group publicly claimed responsibility, and victims have expanded to include a range of organizations beyond Klue’s direct customers.
- Investigations by Huntress and ReliaQuest reveal operational details about token use and API querying that facilitated data exfiltration.
- Containment actions included token revocation, removal of unauthorized code, disabling affected integrations, and engagement of incident response teams.


