Icarus Lists Huntress and Additional Organizations in Expanding Klue Breach Extortion Campaign

Icarus has added Huntress and four additional organizations to its leak site, claiming to possess Salesforce data allegedly stolen through the Klue compromise.
Icarus leak site displaying alleged Salesforce datasets associated with Huntress and four additional organizations, including HDS Corp, GMS-Net, CQCRM, and CBAssociations, following the Klue supply chain breach.
The Icarus leak site lists Huntress alongside HDS Corp, GMS-Net, CQCRM, and CBAssociations, claiming to possess Salesforce data allegedly obtained through the Klue supply chain compromise. Huntress is listed with a claimed 3.4 GB dataset, while the other organizations are associated with datasets ranging from 20 MB to 3.4 GB.

The Icarus extortion group has expanded its campaign stemming from the Klue supply chain breach, adding Huntress and at least four additional organizations to its leak site while claiming possession of Salesforce data allegedly stolen through compromised OAuth integrations.

Among the newly listed victims is cybersecurity company Huntress, which Icarus claims is associated with a 3.4 GB Salesforce dataset. The leak site also references HDS Corp, GMS-Net, CQCRM, and CBAssociations, each accompanied by separate claims of compressed Salesforce data ranging from approximately 20 MB to 3.4 GB.

The development marks a significant escalation of the incident BreachNews previously covered in Klue Supply Chain Breach Leads to Salesforce Data Theft Across Multiple Organizations, where attackers allegedly harvested OAuth credentials from Klue’s integration infrastructure and used them to access Salesforce environments belonging to downstream customers.

Huntress previously confirmed Salesforce exposure

Unlike several of the newly listed organizations, Huntress has already publicly acknowledged impact from the Klue incident. According to the company’s investigation, attackers accessed data associated with its Salesforce environment after compromising OAuth credentials connected to Klue’s platform.

Huntress previously stated that there was no evidence its products, infrastructure, telemetry, passwords, payment card information, threat intelligence systems, or customer security data were affected by the incident.

In an update published on June 19, Huntress disclosed that the potentially exposed Salesforce information may include business names, products trialed or used, subscription details, pricing information, business contact information, work email addresses, job titles, phone numbers, business addresses, sales and marketing communications, and opportunity notes maintained within the company’s CRM environment.

While Icarus claims to possess 3.4 GB of Huntress Salesforce data, the group has not publicly released evidence sufficient to independently verify the size or contents of the alleged dataset.

Additional organizations added to leak site

Alongside Huntress, Icarus has published new leak site entries for HDS Corp, GMS-Net, CQCRM, and CBAssociations. Each listing references Salesforce data and includes a claimed compressed dataset size, though the group has not provided detailed descriptions regarding the contents of the alleged files.

The leak site currently describes the data simply as Salesforce information associated with each organization. At the time of publication, BreachNews could not independently verify the authenticity of the claims or determine whether any of the organizations had been directly impacted by the Klue compromise.

The appearance of multiple organizations on the leak site may indicate that attackers are moving from extortion attempts toward public disclosure of data allegedly obtained during the campaign.

Supply chain compromise continues to unfold

According to public disclosures from Klue and affected organizations, attackers gained access to Klue’s backend systems and modified infrastructure to collect OAuth credentials used by customers to connect services including Salesforce and other third-party platforms.

Investigators believe the threat actor subsequently used those credentials to query customer Salesforce environments and exfiltrate data from multiple organizations.

Several companies, including Huntress, Recorded Future, Tanium, and Jamf, have previously acknowledged impacts associated with the incident, though the scope of exposure varies between victims.

The emergence of leak site listings tied to the campaign suggests the incident may be entering a new phase as Icarus attempts to pressure organizations through public exposure and extortion.

Investigation remains ongoing

At the time of publication, Huntress had not issued any public statement specifically addressing its appearance on the Icarus leak site.

BreachNews will update this article if Huntress or any of the other listed organizations provide additional information regarding the alleged datasets.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map