Klue Battlecards app Salesforce customer data leak
Data Leak
Summary
Hide ▲
Show ▼
A Klue-related Salesforce data leak on June 12 exposed customer records after an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastructure and access connected environments. Huntress and ReliaQuest tied the activity to stolen integration access, Python scripting, and bulk Salesforce REST API querying, and Icarus has now publicly claimed responsibility on its leak site. Additional affected organizations have disclosed impacts, while most say the exposure was limited to Salesforce instances rather than their core platforms or infrastructure.
Related Happenings
Klue hit by network compromise
Incident
H score39
First: 18.06.2026 17:19
Last: 18.06.2026 17:19
Sources 1
How related:
Klue said it detected unauthorized activity affecting a portion of Klue's integration infrastructure on June 12, 2026, adding the attackers gained access through a compromised legacy credential associated with an integration service.
About this happening:
Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastru...
Klue hit by network compromise
IncidentHow related: Klue said it detected unauthorized activity affecting a portion of Klue's integration infrastructure on June 12, 2026, adding the attackers gained access through a compromised legacy credential associated with an integration service.
About this happening: Klue confirmed a June 12, 2026 security incident in which an attacker used a compromised legacy credential to obtain OAuth tokens from Klue’s integration infrastru...
Latest development: 23.06.2026 16:58
Unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in LastPass's Salesforce environment. LastPass said its products, services, infrastructure, and customer vaults were not affected, and it disabled employee access to Klue, rotated exposed API/OAuth tokens, and notified law enforcement.
Icarus Salesforce data-theft extortion campaign
Campaign
H score42
First: 18.06.2026 17:19
Last: 18.06.2026 17:19
Sources 1
How related:
The Klue supply chain attack was claimed by the Icarus extortion group, who compromised the infrastructure of the AI-powered market intelligence platform and stole OAuth tokens that connected customers' Salesforce environments.
About this happening:
The Icarus extortion campaign is actively stealing Salesforce CRM data from multiple organizations, expanding pressure on victims and showing a repeatable cloud-app ab...
Icarus Salesforce data-theft extortion campaign
CampaignHow related: The Klue supply chain attack was claimed by the Icarus extortion group, who compromised the infrastructure of the AI-powered market intelligence platform and stole OAuth tokens that connected customers' Salesforce environments.
About this happening: The Icarus extortion campaign is actively stealing Salesforce CRM data from multiple organizations, expanding pressure on victims and showing a repeatable cloud-app ab...
Latest development: 23.06.2026 16:58
LastPass says an unauthorized actor used OAuth tokens stolen from Klue to access LastPass customer data in its Salesforce environment, potentially exposing customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM data; LastPass says its products, services, infrastructure, and customer vaults were not affected, rotated the exposed API/OAuth tokens, disabled employee access to Klue, and notified law enforcement.
University of Nottingham hit by cyberattack
Incident
H score68
First: 11.06.2026 10:27
Last: 11.06.2026 10:27
Sources 1
About this happening:
The University of Nottingham said a well-known cybercriminal group accessed its student record system, exposing a significant amount of data affecting current students and...
University of Nottingham hit by cyberattack
IncidentAbout this happening: The University of Nottingham said a well-known cybercriminal group accessed its student record system, exposing a significant amount of data affecting current students and...
Nottingham University data publication on ShinyHunters leak site
Data Leak
H score68
First: 10.06.2026 21:31
Last: 10.06.2026 21:31
Sources 1
About this happening:
Nottingham University data was published on the ShinyHunters leak site after the group claimed access to the university’s student records system. The exposed material...
Nottingham University data publication on ShinyHunters leak site
Data LeakAbout this happening: Nottingham University data was published on the ShinyHunters leak site after the group claimed access to the university’s student records system. The exposed material...
Carnival Corporation customer data leak
Data Leak
H score60
First: 28.05.2026 13:49
Last: 28.05.2026 13:49
Sources 1
About this happening:
Carnival Corporation confirmed a customer data leak that exposed personal information for 5,995,277 people, making this a large-scale privacy and identity-risk event....
Carnival Corporation customer data leak
Data LeakAbout this happening: Carnival Corporation confirmed a customer data leak that exposed personal information for 5,995,277 people, making this a large-scale privacy and identity-risk event....
Timeline
-
20.06.2026 01:31 1 articles · 26d ago
Icarus claims Klue Salesforce data theft as victim list expands
Attribution UpdateIcarus publicly claimed responsibility on its data leak site for the Klue-related Salesforce data theft and pressured Klue and affected organizations to contact the group through Session to avoid publication of stolen data. The same campaign was also tied to additional victims including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity, with most reporting theft from Salesforce instances rather than compromise of their core platforms or infrastructure.
Show sources
- Klue OAuth breach victim list grows as Icarus hackers claim attack — www.bleepingcomputer.com — 20.06.2026 01:31
-
19.06.2026 12:03 1 articles · 26d ago
Klue integration service compromise exposes Salesforce-connected customer data
Exploitation ObservedA compromised legacy credential associated with Klue's integration service was used on June 11, 2026 to obtain OAuth tokens for third-party connections, allowing access to data in connected customer environments tied to Salesforce.
Show sources
- Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data — thehackernews.com — 19.06.2026 12:03
-
19.06.2026 12:03 1 articles · 26d ago
Klue detects unauthorized activity in integration infrastructure
Detection Ioc UpdateKlue said it detected unauthorized activity affecting part of its integration infrastructure on June 12, 2026, and linked the access to a compromised legacy credential that let an attacker obtain OAuth tokens for connected platforms including Salesforce.
Show sources
- Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data — thehackernews.com — 19.06.2026 12:03
-
19.06.2026 12:03 3 articles · 26d ago
Huntress employees receive extortion emails over copied Salesforce data
Victim Impact UpdateAs of June 16, 2026, some Huntress employees received extortion emails stating that Salesforce data had been downloaded, and Huntress said the copied data included business contacts, price quotes, and other sales-related data and messaging.
Show sources
- Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data — thehackernews.com — 19.06.2026 12:03
- Klue Breach Enables Hackers to Compromise Cybersecurity Firms via OAuth Tokens — www.infosecurity-magazine.com — 22.06.2026 13:15
- LastPass confirms data breach in Klue supply chain attack — www.bleepingcomputer.com — 23.06.2026 16:58
-
19.06.2026 12:03 2 articles · 26d ago
Salesforce disables the Klue Battlecards app integration
Technical Analysis UpdateSalesforce said it disabled the Klue Battlecards app integration after security teams detected unusual activity that may have exposed a subset of customer data via the app's connection to Salesforce, while ReliaQuest said the activity involved compromised Klue integration access, OAuth tokens, and automated Python scripts that queried the Salesforce REST API for almost 24 hours.
Show sources
- Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data — thehackernews.com — 19.06.2026 12:03
- Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data — thehackernews.com — 19.06.2026 12:03