Icarus Salesforce data-theft extortion campaign
Campaign
Summary
Hide ▲
Show ▼
The Icarus extortion campaign is actively stealing Salesforce CRM data from multiple organizations, expanding pressure on victims and showing a repeatable cloud-app abuse pattern. The operation uses stolen OAuth tokens and automated queries against Salesforce REST API endpoints to map objects and pull records. Victims then receive extortion emails tied to the alias mr bean, while leak-site messaging signals continuing activity.
Related Happenings
Helix vishing and SharePoint data-extortion campaign
Campaign
H score38
First: 09.07.2026 20:08
Last: 09.07.2026 20:08
Sources 1
About this happening:
The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Helix vishing and SharePoint data-extortion campaign
CampaignAbout this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...
Klue Battlecards app Salesforce customer data leak
Data Leak
H score41
First: 19.06.2026 12:03
Last: 19.06.2026 12:03
Sources 1
How related:
“The threat actor then used these credentials to access LastPass customer data within our Salesforce environment.”
About this happening:
A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue...
Klue Battlecards app Salesforce customer data leak
Data LeakHow related: “The threat actor then used these credentials to access LastPass customer data within our Salesforce environment.”
About this happening: A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue...
Latest development: 20.06.2026 01:31
Icarus publicly claimed responsibility on its data leak site for the Klue-related Salesforce data theft and pressured Klue and affected organizations to contact the group through Session to avoid publication of stolen data. The same campaign was also tied to additional victims including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity, with most reporting theft from Salesforce instances rather than compromise of their core platforms or infrastructure.
Klue hit by network compromise
Incident
H score39
First: 18.06.2026 17:19
Last: 18.06.2026 17:19
Sources 1
How related:
According to Huntress, Klue told customers that attackers first compromised the company's backend systems and then pushed a malicious code update that stole OAuth tokens customers use to integrate the Battlecards product with third-party platforms.
About this happening:
Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastru...
Klue hit by network compromise
IncidentHow related: According to Huntress, Klue told customers that attackers first compromised the company's backend systems and then pushed a malicious code update that stole OAuth tokens customers use to integrate the Battlecards product with third-party platforms.
About this happening: Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastru...
Latest development: 23.06.2026 16:58
Unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in LastPass's Salesforce environment. LastPass said its products, services, infrastructure, and customer vaults were not affected, and it disabled employee access to Klue, rotated exposed API/OAuth tokens, and notified law enforcement.
Infostealer malware operation targeting online store users
Malware Activity
H score32
First: 21.05.2026 00:36
Last: 21.05.2026 00:36
Sources 1
About this happening:
A malware operation using infostealer tools infected users’ devices between 2024 and 2025, stealing browser sessions and account credentials that enabled account theft...
Infostealer malware operation targeting online store users
Malware ActivityAbout this happening: A malware operation using infostealer tools infected users’ devices between 2024 and 2025, stealing browser sessions and account credentials that enabled account theft...
BlackFile vishing extortion campaign targeting retail and hospitality organizations
Campaign
H score37
First: 24.04.2026 21:26
Last: 24.04.2026 21:26
Sources 1
About this happening:
The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...
BlackFile vishing extortion campaign targeting retail and hospitality organizations
CampaignAbout this happening: The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...
Timeline
-
23.06.2026 16:58 1 articles · 22d ago
Klue OAuth tokens expose LastPass Salesforce customer data
Victim Impact UpdateLastPass says an unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in its Salesforce environment, potentially exposing customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM data; LastPass says its products, services, infrastructure, and customer vaults were not affected, rotated the exposed API/OAuth tokens, disabled employee access to Klue, and notified law enforcement.
Show sources
- LastPass confirms data breach in Klue supply chain attack — www.bleepingcomputer.com — 23.06.2026 16:58
-
18.06.2026 17:19 2 articles · 27d ago
Icarus-linked OAuth breach steals Salesforce data from multiple organizations
Initial DisclosureKlue's Battlecards integration was implicated in an OAuth breach that let Icarus steal Salesforce CRM data from multiple organizations, with ReliaQuest and Huntress describing token theft, automated Salesforce API querying, and extortion emails sent to impacted Klue customers. Salesforce disabled the Klue Battlecards integration while the breach was investigated.
Show sources
- Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks — www.bleepingcomputer.com — 18.06.2026 17:19
- Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks — www.bleepingcomputer.com — 18.06.2026 17:19