The threat actor group Icarus executed a supply chain attack by compromising the backend systems of the Klue 'Battlecards' integration service. By harvesting stored OAuth tokens, attackers bypassed traditional perimeter security and multi-factor authentication (MFA) to impersonate the trusted Klue application within customer Salesforce CRM instances. Utilizing the Salesforce REST API, the actors performed bulk exfiltration of sensitive enterprise data, including customer records and sales pipelines. This incident highlights the systemic risk posed by third-party SaaS integrations, where a compromise of a trusted service provider facilitates unauthorized, authenticated access to interconnected enterprise environments.
-
Incident Overview: Klue-to-Salesforce Breach
- Target: Klue backend infrastructure and the specifically targeted 'Battlecards' integration service.
- Primary Impact: Unauthorized, authenticated access to downstream Salesforce CRM environments.
- Core Risk: The exploitation of trusted third-party service identities to bypass identity perimeters.
-
Attack Mechanics: OAuth Token Impersonation
- Attack Vector: Theft of stored OAuth tokens from Klue’s integration service accounts.
- Execution Method: Direct querying of Salesforce REST APIs using the stolen, valid tokens.
- Security Bypass: The use of valid application-level tokens allowed attackers to circumvent MFA and traditional user-login-based security controls.
-
Threat Group Profile & Scale of Impact
- Actor Identity: Icarus, an extortion-focused threat group.
- Victim Profile: Multiple enterprises, including high-value targets like Managed Service Providers (MSPs) and cybersecurity firms.
- Data Loss: Bulk exfiltration of sensitive customer records, sales pipelines, and enterprise contact information.
- Exploitation Window: At least 24 hours of continuous, automated CRM data extraction.
-
Detection and Mitigation
- Platform Action: Salesforce disabled the Klue Battlecards app integration on June 11, 2026, to halt the breach.
- Detection Indicators: CRM access logs showing high-volume API calls originating from the Klue integration without corresponding user authentication events.
- Active Threat: Ongoing extortion campaigns leveraging the stolen CRM intelligence.
Related posts
- reliaquest.com — Klue Integration Abused in Salesforce Data Theft
- SC Media — Icarus threat actors exploit Klue OAuth breach to steal Salesforce data
- techjacksolutions.com — Icarus Exploits Klue OAuth Chain to Exfiltrate Salesforce CRM Data Across Multiple Enterprises
- techjacksolutions.com — Salesforce Third-Party App Compromise Campaign Expands: Klue Battlecards Joins Growing Supply Chain Attack Series
- techjacksolutions.com — Salesforce Data Exfiltration via Klue OAuth Integration Compromise
- gbhackers.com — Hackers Exploit Klue Integration to Steal Salesforce CRM Data Using OAuth Tokens
- feeds.feedburner.com — Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
- helpnetsecurity.com — Klue breach lead to Salesforce data theft, Huntress affected
- Obsidiansecurity
- Status
- bleepingcomputer.com — Klue OAuth breach victim list grows as Icarus hackers claim attack
- Ampcuscyber
- Recordedfuture
- Rescana
- Tanium
- Dexpose
- Ghost-protocol
- Threatcodex
- techjacksolutions.com — Icarus Threat Actor Exploits Klue OAuth Tokens to Breach Multiple Salesforce Environments
- bleepingcomputer.com — LastPass confirms data breach in Klue supply chain attack
- techjacksolutions.com — Klue / Salesforce (Third-Party Integration) — Vulnerability Rollup (2026-06-26)
- Huntress
- Darkreading
- Salesforceben
- Kudelskisecurity
- Techechelon
- Govinfosecurity
- Radar
- Csidb
- Thecybersecguru
- Socdefenders
- News4Hackers — Salesforce Disables Klue Integration Over OAuth Token Theft Risk to Customer Data
- techjacksolutions.com — Salesforce — Vulnerability Rollup (2026-06-18)
- Aiweekly
- threatlocker.com — Klue: SaaS supply chain compromise through long-lived OAuth tokens
- threat-modeling.com — Icarus Threat Actor Expands Klue OAuth Breach with Salesforce Data Theft Attacks
- csoonline.com — Klue breach exposed Salesforce CRM data through stolen OAuth tokens
- fieldeffect.com — Klue integration breach exposes Salesforce customer data
- cybersecuritydive.com — Klue investigating supply chain attack that targeted Salesforce integrations
- Iansresearch
- App
- Rhisac
- Rodtrent
- Techradar
- Securitylabs
- Galaxywarden
- Obsidiansecurity
- Blog
- Klue
- Medium
- Youtube
- Hawk-eye
- Thenextweb
- Channelinsider
- Beazley
- Mashable
- Computing
- Pcmag
- Upguard
- Thenextweb
- Zscaler
- SecurityWeek — BeyondTrust, LastPass Impacted by Klue-Salesforce Incident
- SecurityWeek — More Klue Breach Victims Identified as Hackers Get Hacked