Find notable cyber news and cases, enriched with sources, timelines, and signals.

Klue Battlecards app Salesforce customer data leak

Data Leak
First reported
Last updated
Happening score
H score 41
3 unique sources, 4 articles

Summary

Hide ▲

A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastructure and access connected environments. Huntress and ReliaQuest tied the activity to stolen integration access, Python scripting, and bulk Salesforce REST API querying, and Icarus has now publicly claimed responsibility on its leak site. Additional affected organizations have disclosed impacts, while most say the exposure was limited to Salesforce instances rather than their core platforms or infrastructure.

Related Happenings

Klue hit by network compromise

Incident
H score39 First: 18.06.2026 17:19 Last: 18.06.2026 17:19 Sources 1

How related: Klue said it detected unauthorized activity affecting a portion of Klue's integration infrastructure on June 12, 2026, adding the attackers gained access through a compromised legacy credential associated with an integration service.

About this happening: Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastru...

Latest development: 23.06.2026 16:58

Unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in LastPass's Salesforce environment. LastPass said its products, services, infrastructure, and customer vaults were not affected, and it disabled employee access to Klue, rotated exposed API/OAuth tokens, and notified law enforcement.

Icarus Salesforce data-theft extortion campaign

Campaign
H score42 First: 18.06.2026 17:19 Last: 18.06.2026 17:19 Sources 1

How related: The Klue supply chain attack was claimed by the Icarus extortion group, who compromised the infrastructure of the AI-powered market intelligence platform and stole OAuth tokens that connected customers' Salesforce environments.

About this happening: The Icarus extortion campaign is actively stealing Salesforce CRM data from multiple organizations, expanding pressure on victims and showing a repeatable cloud-app ab...

Latest development: 23.06.2026 16:58

LastPass says an unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in its Salesforce environment, potentially exposing customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM data; LastPass says its products, services, infrastructure, and customer vaults were not affected, rotated the exposed API/OAuth tokens, disabled employee access to Klue, and notified law enforcement.

University of Nottingham hit by cyberattack

Incident
H score68 First: 11.06.2026 10:27 Last: 11.06.2026 10:27 Sources 1

About this happening: The University of Nottingham said a well-known cybercriminal group accessed its student record system, exposing a significant amount of data affecting current students and...

Nottingham University data publication on ShinyHunters leak site

Data Leak
H score68 First: 10.06.2026 21:31 Last: 10.06.2026 21:31 Sources 1

About this happening: Nottingham University data was published on the ShinyHunters leak site after the group claimed access to the university’s student records system. The exposed material...

Carnival Corporation customer data leak

Data Leak
H score60 First: 28.05.2026 13:49 Last: 28.05.2026 13:49 Sources 1

About this happening: Carnival Corporation confirmed a customer data leak that exposed personal information for 5,995,277 people, making this a large-scale privacy and identity-risk event....

Timeline

  1. 20.06.2026 01:31 1 articles · 26d ago

    Icarus claims Klue Salesforce data theft as victim list expands

    Attribution Update

    Icarus publicly claimed responsibility on its data leak site for the Klue-related Salesforce data theft and pressured Klue and affected organizations to contact the group through Session to avoid publication of stolen data. The same campaign was also tied to additional victims including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity, with most reporting theft from Salesforce instances rather than compromise of their core platforms or infrastructure.

    Show sources
  2. 19.06.2026 12:03 1 articles · 26d ago

    Klue integration service compromise exposes Salesforce-connected customer data

    Exploitation Observed

    A compromised legacy credential associated with Klue's integration service was used on June 11, 2026 to obtain OAuth tokens for third-party connections, allowing access to data in connected customer environments tied to Salesforce.

    Show sources
  3. 19.06.2026 12:03 1 articles · 26d ago

    Klue detects unauthorized activity in integration infrastructure

    Detection Ioc Update

    Klue said it detected unauthorized activity affecting part of its integration infrastructure on June 12, 2026, and linked the access to a compromised legacy credential that let an attacker obtain OAuth tokens for connected platforms including Salesforce.

    Show sources
  4. 19.06.2026 12:03 3 articles · 26d ago

    Huntress employees receive extortion emails over copied Salesforce data

    Victim Impact Update

    As of June 16, 2026, some Huntress employees received extortion emails stating that Salesforce data had been downloaded, and Huntress said the copied data included business contacts, price quotes, and other sales-related data and messaging.

    Show sources
  5. 19.06.2026 12:03 2 articles · 26d ago

    Salesforce disables the Klue Battlecards app integration

    Technical Analysis Update

    Salesforce said it disabled the Klue Battlecards app integration after security teams detected unusual activity that may have exposed a subset of customer data via the app's connection to Salesforce, while ReliaQuest said the activity involved compromised Klue integration access, OAuth tokens, and automated Python scripts that queried the Salesforce REST API for almost 24 hours.

    Show sources