Find notable cyber news and cases, enriched with sources, timelines, and signals.

Icarus Salesforce data-theft extortion campaign

Campaign
First reported
Last updated
Happening score
H score 42
1 unique sources, 2 articles

Summary

Hide ▲

The Icarus extortion campaign is actively stealing Salesforce CRM data from multiple organizations, expanding pressure on victims and showing a repeatable cloud-app abuse pattern. The operation uses stolen OAuth tokens and automated queries against Salesforce REST API endpoints to map objects and pull records. Victims then receive extortion emails tied to the alias mr bean, while leak-site messaging signals continuing activity.

Related Happenings

Helix vishing and SharePoint data-extortion campaign

Campaign
H score38 First: 09.07.2026 20:08 Last: 09.07.2026 20:08 Sources 1

About this happening: The Helix campaign is using vishing, device-code phishing, and MFA abuse to break into SharePoint environments and steal files, exposing victim organizations t...

Klue Battlecards app Salesforce customer data leak

Data Leak
H score41 First: 19.06.2026 12:03 Last: 19.06.2026 12:03 Sources 1

How related: “The threat actor then used these credentials to access LastPass customer data within our Salesforce environment.”

About this happening: A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue...

Latest development: 20.06.2026 01:31

Icarus publicly claimed responsibility on its data leak site for the Klue-related Salesforce data theft and pressured Klue and affected organizations to contact the group through Session to avoid publication of stolen data. The same campaign was also tied to additional victims including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity, with most reporting theft from Salesforce instances rather than compromise of their core platforms or infrastructure.

Klue hit by network compromise

Incident
H score39 First: 18.06.2026 17:19 Last: 18.06.2026 17:19 Sources 1

How related: According to Huntress, Klue told customers that attackers first compromised the company's backend systems and then pushed a malicious code update that stole OAuth tokens customers use to integrate the Battlecards product with third-party platforms.

About this happening: Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastru...

Latest development: 23.06.2026 16:58

Unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in LastPass's Salesforce environment. LastPass said its products, services, infrastructure, and customer vaults were not affected, and it disabled employee access to Klue, rotated exposed API/OAuth tokens, and notified law enforcement.

Infostealer malware operation targeting online store users

Malware Activity
H score32 First: 21.05.2026 00:36 Last: 21.05.2026 00:36 Sources 1

About this happening: A malware operation using infostealer tools infected users’ devices between 2024 and 2025, stealing browser sessions and account credentials that enabled account theft...

BlackFile vishing extortion campaign targeting retail and hospitality organizations

Campaign
H score37 First: 24.04.2026 21:26 Last: 24.04.2026 21:26 Sources 1

About this happening: The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...

Timeline

  1. 23.06.2026 16:58 1 articles · 22d ago

    Klue OAuth tokens expose LastPass Salesforce customer data

    Victim Impact Update

    LastPass says an unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in its Salesforce environment, potentially exposing customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM data; LastPass says its products, services, infrastructure, and customer vaults were not affected, rotated the exposed API/OAuth tokens, disabled employee access to Klue, and notified law enforcement.

    Show sources
  2. 18.06.2026 17:19 2 articles · 27d ago

    Icarus-linked OAuth breach steals Salesforce data from multiple organizations

    Initial Disclosure

    Klue's Battlecards integration was implicated in an OAuth breach that let Icarus steal Salesforce CRM data from multiple organizations, with ReliaQuest and Huntress describing token theft, automated Salesforce API querying, and extortion emails sent to impacted Klue customers. Salesforce disabled the Klue Battlecards integration while the breach was investigated.

    Show sources