Find notable cyber news and cases, enriched with sources, timelines, and signals.

Klue hit by network compromise

Incident
First reported
Last updated
Happening score
H score 39
3 unique sources, 5 articles

Summary

Hide ▲

Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastructure and access data in connected Salesforce environments. The activity is now publicly claimed by Icarus, which said Klue.com was impacted and that partner Salesforce instances were exfiltrated. Reports from Huntress and ReliaQuest tie the theft to automated Python scripts and Salesforce API querying, with affected organizations including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. Klue says the incident was limited to third-party integrations and that there is no evidence customer content stored directly in the Klue platform was impacted.

Related Happenings

Klue Battlecards app Salesforce customer data leak

Data Leak
H score41 First: 19.06.2026 12:03 Last: 19.06.2026 12:03 Sources 1

How related: Huntress later disclosed that its own Salesforce environment was affected by the Klue breach and that the stolen data included business contacts, sales communications, pricing information, and other records.

About this happening: A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue...

Latest development: 20.06.2026 01:31

Icarus publicly claimed responsibility on its data leak site for the Klue-related Salesforce data theft and pressured Klue and affected organizations to contact the group through Session to avoid publication of stolen data. The same campaign was also tied to additional victims including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity, with most reporting theft from Salesforce instances rather than compromise of their core platforms or infrastructure.

Icarus Salesforce data-theft extortion campaign

Campaign
H score42 First: 18.06.2026 17:19 Last: 18.06.2026 17:19 Sources 1

How related: Market intelligence platform Klue suffered a OAuth breach that enabled the "Icarus" threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign.

About this happening: The Icarus extortion campaign is actively stealing Salesforce CRM data from multiple organizations, expanding pressure on victims and showing a repeatable cloud-app ab...

Latest development: 23.06.2026 16:58

LastPass says an unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in its Salesforce environment, potentially exposing customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM data; LastPass says its products, services, infrastructure, and customer vaults were not affected, rotated the exposed API/OAuth tokens, disabled employee access to Klue, and notified law enforcement.

Major U.S. services company hit by ransomware attack linked to DragonForce

Incident
H score38 First: 16.06.2026 13:18 Last: 16.06.2026 13:18 Sources 1

About this happening: A DragonForce ransomware incident hit a major U.S. services firm in December 2025, with attackers maintaining access for one to two months and hiding command-and...

BlackFile vishing extortion campaign targeting retail and hospitality organizations

Campaign
H score37 First: 24.04.2026 21:26 Last: 24.04.2026 21:26 Sources 1

About this happening: The BlackFile campaign is driving vishing-based data theft and extortion against retail and hospitality organizations, putting employee credentials and enterprise data...

Over a dozen companies data exposed after SaaS integration provider Snowflake breach

Data Leak
H score69 First: 07.04.2026 22:39 Last: 07.04.2026 22:39 Sources 1

About this happening: A stolen-token attack from a SaaS integration provider breach has led to data theft claims affecting over a dozen companies, creating immediate exposure and extortion risk...

Timeline

  1. 23.06.2026 16:58 1 articles · 22d ago

    LastPass customer data accessed through stolen Klue OAuth tokens

    Victim Impact Update

    Unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in LastPass's Salesforce environment. LastPass said its products, services, infrastructure, and customer vaults were not affected, and it disabled employee access to Klue, rotated exposed API/OAuth tokens, and notified law enforcement.

    Show sources
  2. 20.06.2026 01:31 1 articles · 26d ago

    Icarus claims responsibility for Klue compromise

    Attribution Update

    Icarus publicly claimed responsibility for the Klue compromise on its data leak site, saying Klue.com was impacted and that partner Salesforce instances were exfiltrated. The group also pressured Klue and affected organizations to contact it through Session to stop the stolen data from being leaked.

    Show sources
  3. 18.06.2026 17:19 4 articles · 27d ago

    Klue OAuth breach lets Icarus steal Salesforce CRM data

    Initial Disclosure

    Klue suffered an OAuth breach that enabled Icarus to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign. ReliaQuest and Huntress said attackers used stolen OAuth tokens and automated Python scripts against Salesforce APIs, while Salesforce disabled the Klue Battlecards integration during the investigation. Huntress said the stolen data included business contacts, sales communications, price quotes, competitive intelligence reports, and account data.

    Show sources