Klue hit by network compromise
Incident
Summary
Hide ▲
Show ▼
Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastructure and access data in connected Salesforce environments. The activity is now publicly claimed by Icarus, which said Klue.com was impacted and that partner Salesforce instances were exfiltrated. Reports from Huntress and ReliaQuest tie the theft to automated Python scripts and Salesforce API querying, with affected organizations including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. Klue says the incident was limited to third-party integrations and that there is no evidence customer content stored directly in the Klue platform was impacted.
Related Happenings
Klue Battlecards app Salesforce customer data leak
Data Leak
H score41
First: 19.06.2026 12:03
Last: 19.06.2026 12:03
Sources 1
How related:
Huntress later disclosed that its own Salesforce environment was affected by the Klue breach and that the stolen data included business contacts, sales communications, pricing information, and other records.
About this happening:
A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue...
Klue Battlecards app Salesforce customer data leak
Data LeakHow related: Huntress later disclosed that its own Salesforce environment was affected by the Klue breach and that the stolen data included business contacts, sales communications, pricing information, and other records.
About this happening: A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue...
Latest development: 20.06.2026 01:31
Icarus publicly claimed responsibility on its data leak site for the Klue-related Salesforce data theft and pressured Klue and affected organizations to contact the group through Session to avoid publication of stolen data. The same campaign was also tied to additional victims including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity, with most reporting theft from Salesforce instances rather than compromise of their core platforms or infrastructure.
Icarus Salesforce data-theft extortion campaign
Campaign
H score42
First: 18.06.2026 17:19
Last: 18.06.2026 17:19
Sources 1
How related:
Market intelligence platform Klue suffered a OAuth breach that enabled the "Icarus" threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign.
About this happening:
The Icarus extortion campaign is actively stealing Salesforce CRM data from multiple organizations, expanding pressure on victims and showing a repeatable cloud-app ab...
Icarus Salesforce data-theft extortion campaign
CampaignHow related: Market intelligence platform Klue suffered a OAuth breach that enabled the "Icarus" threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign.
About this happening: The Icarus extortion campaign is actively stealing Salesforce CRM data from multiple organizations, expanding pressure on victims and showing a repeatable cloud-app ab...
Latest development: 23.06.2026 16:58
LastPass says an unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in its Salesforce environment, potentially exposing customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM data; LastPass says its products, services, infrastructure, and customer vaults were not affected, rotated the exposed API/OAuth tokens, disabled employee access to Klue, and notified law enforcement.
Major U.S. services company hit by ransomware attack linked to DragonForce
Incident
H score38
First: 16.06.2026 13:18
Last: 16.06.2026 13:18
Sources 1
About this happening:
A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
Major U.S. services company hit by ransomware attack linked to DragonForce
IncidentAbout this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...
BlackFile vishing extortion campaign targeting retail and hospitality organizations
Campaign
H score37
First: 24.04.2026 21:26
Last: 24.04.2026 21:26
Sources 1
About this happening:
The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...
BlackFile vishing extortion campaign targeting retail and hospitality organizations
CampaignAbout this happening: The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...
Over a dozen companies data exposed after SaaS integration provider Snowflake breach
Data Leak
H score69
First: 07.04.2026 22:39
Last: 07.04.2026 22:39
Sources 1
About this happening:
A stolen-token attack from a SaaS integration provider breach has led to data theft claims affecting over a dozen companies, creating immediate exposure and extortion risk...
Over a dozen companies data exposed after SaaS integration provider Snowflake breach
Data LeakAbout this happening: A stolen-token attack from a SaaS integration provider breach has led to data theft claims affecting over a dozen companies, creating immediate exposure and extortion risk...
Timeline
-
23.06.2026 16:58 1 articles · 22d ago
LastPass customer data accessed through stolen Klue OAuth tokens
Victim Impact UpdateUnauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in LastPass's Salesforce environment. LastPass said its products, services, infrastructure, and customer vaults were not affected, and it disabled employee access to Klue, rotated exposed API/OAuth tokens, and notified law enforcement.
Show sources
- LastPass confirms data breach in Klue supply chain attack — www.bleepingcomputer.com — 23.06.2026 16:58
-
20.06.2026 01:31 1 articles · 26d ago
Icarus claims responsibility for Klue compromise
Attribution UpdateIcarus publicly claimed responsibility for the Klue compromise on its data leak site, saying Klue.com was impacted and that partner Salesforce instances were exfiltrated. The group also pressured Klue and affected organizations to contact it through Session to stop the stolen data from being leaked.
Show sources
- Klue OAuth breach victim list grows as Icarus hackers claim attack — www.bleepingcomputer.com — 20.06.2026 01:31
-
18.06.2026 17:19 4 articles · 27d ago
Klue OAuth breach lets Icarus steal Salesforce CRM data
Initial DisclosureKlue suffered an OAuth breach that enabled Icarus to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign. ReliaQuest and Huntress said attackers used stolen OAuth tokens and automated Python scripts against Salesforce APIs, while Salesforce disabled the Klue Battlecards integration during the investigation. Huntress said the stolen data included business contacts, sales communications, price quotes, competitive intelligence reports, and account data.
Show sources
- Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks — www.bleepingcomputer.com — 18.06.2026 17:19
- Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks — www.bleepingcomputer.com — 18.06.2026 17:19
- Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data — thehackernews.com — 19.06.2026 12:03
- Klue Breach Enables Hackers to Compromise Cybersecurity Firms via OAuth Tokens — www.infosecurity-magazine.com — 22.06.2026 13:15