Klue Supply Chain Breach Leads to Salesforce Data Theft Across Multiple Organizations

A compromise of Klue’s integration infrastructure allowed attackers to steal OAuth tokens and access Salesforce environments belonging to multiple organizations.
Screenshot of the Icarus leak site showing Klue listed as a victim. The page claims Salesforce data from multiple organizations was exfiltrated through a compromise of Klue and includes an extortion message directed at affected companies.
Screenshot from the Icarus leak site referencing the alleged compromise of Klue and claiming access to Salesforce data belonging to multiple partner organizations. Researchers have linked the listing to a broader supply chain attack involving stolen OAuth credentials.

Update (July 6, 2026): Since publication, additional organizations have confirmed they were affected by the Klue supply chain compromise, including LastPass, HackerOne, OneTrust, Snyk, Insurity, Sprout Social, and Gong. Klue has also provided additional details on the incident, stating that attackers gained access using a compromised legacy credential before harvesting OAuth tokens used by customer integrations. Huntress continues to attribute the campaign with high confidence to the Icarus extortion group, which has expanded its leak site with additional alleged victims tied to the incident.


A compromise of competitive intelligence platform Klue has resulted in the theft of Salesforce CRM data from multiple organizations after attackers allegedly harvested OAuth credentials from Klue’s integration infrastructure and used them to access customer environments.

The incident has been linked to a newly emerged extortion operation calling itself Icarus, which has already begun contacting affected organizations and threatening public disclosure of stolen data.

According to a detailed incident report published by Huntress, attackers gained access to Klue’s backend systems, collected OAuth tokens used to connect customer software platforms, and subsequently queried Salesforce environments belonging to Klue customers. Several organizations, including Huntress, Recorded Future, Tanium, and Jamf, have publicly acknowledged impacts related to the incident.

Attackers allegedly harvested customer OAuth tokens

According to information shared by Klue and Huntress, suspicious activity was first detected on June 12 after attackers reportedly gained access to systems supporting Klue’s third-party integrations.

Investigators believe the compromise originated from a long-unused credential originally created for a third-party integration project. After gaining access, the threat actor allegedly modified backend systems to collect OAuth credentials used by customers to connect services including Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack.

Klue subsequently revoked customer OAuth credentials and temporarily disabled multiple integrations while conducting its investigation.

Huntress reported that attackers then used the harvested credentials to directly query customer Salesforce environments and exfiltrate data from affected organizations.

Security vendors disclose impact

Huntress confirmed that data associated with its Salesforce environment was accessed during the incident. According to the company, the compromised information may include business contacts, subscription details, pricing information, sales communications, opportunity notes, and other CRM-related records.

The company stated there was no evidence that Huntress products, infrastructure, telemetry, passwords, payment card information, threat intelligence systems, or customer security data were affected.

Recorded Future, Tanium, Jamf, LastPass, HackerOne, OneTrust, Snyk, Insurity, Sprout Social, and Gong have all publicly acknowledged impacts stemming from the Klue incident, though the scope of data exposure varies between organizations and investigations remain ongoing.

Salesforce reportedly disabled Klue’s Battlecards integration following discovery of the compromise.

Icarus emerges as new extortion operation

The incident has also brought attention to Icarus, a relatively new extortion group that appears to have launched operations earlier this year.

Beginning on June 16, employees at affected organizations reportedly received extortion emails claiming that Salesforce data had been downloaded through the Klue breach. The messages instructed recipients to communicate with the attackers through the Session encrypted messaging platform and warned that data could be publicly disclosed if contact was not established.

Researchers later identified matching Session identifiers on the Icarus leak site, leading Huntress to conclude with high confidence that the group was responsible for both the compromise and subsequent extortion activity.

Screenshots published by Huntress show Icarus listing Klue on its leak site while claiming that Salesforce environments belonging to multiple partner organizations had been exfiltrated.

Supply chain attacks continue to expand

The incident highlights the growing risks associated with SaaS integrations and trusted OAuth relationships between organizations and third-party providers.

The group appears to have been active since at least May 2026. Prior to the Klue incident, Icarus publicly claimed responsibility for an alleged breach of Indonesian fintech provider Cazh.id, asserting that it possessed customer records, identity verification documents, educational databases, and source code. Those claims were not independently verified, and no public confirmation of an incident was identified.

Unlike traditional data breaches that target a single organization, supply chain attacks frequently allow threat actors to leverage one compromise into access across numerous downstream customers.

Throughout 2026, BreachNews has covered multiple software supply chain incidents, including the Bitwarden CLI supply chain attack, the Miasma npm campaign, the Mini Shai-Hulud attacks, TeamPCP-related software compromise activity, the expanding Icarus extortion campaign, and LastPass’ confirmation of customer support data theft following the Klue breach.

Investigations by Klue, Huntress, and other affected organizations remain ongoing.

Klue has issued notifications to affected customers and continues to provide incident updates while organizations review Salesforce access logs, rotate OAuth credentials, and assess the scope of any unauthorized data access resulting from the compromise.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site
INTEL.BREACHNEWS.COM

Live Cyber
Threat Map

Explore live cyber activity, recent breach reports, KEV alerts, and public threat feeds from a single interactive dashboard.

Launch Threat Map