← Back to Daily Briefing

The threat actor group Icarus executed a supply chain attack by compromising the backend systems of the Klue 'Battlecards' integration service. By harvesting stored OAuth tokens, attackers bypassed traditional perimeter security and multi-factor authentication (MFA) to impersonate the trusted Klue application within customer Salesforce CRM instances. Utilizing the Salesforce REST API, the actors performed bulk exfiltration of sensitive enterprise data, including customer records and sales pipelines. This incident highlights the systemic risk posed by third-party SaaS integrations, where a compromise of a trusted service provider facilitates unauthorized, authenticated access to interconnected enterprise environments.

  • Incident Overview: Klue-to-Salesforce Breach

    • Target: Klue backend infrastructure and the specifically targeted 'Battlecards' integration service.
    • Primary Impact: Unauthorized, authenticated access to downstream Salesforce CRM environments.
    • Core Risk: The exploitation of trusted third-party service identities to bypass identity perimeters.
  • Attack Mechanics: OAuth Token Impersonation

    • Attack Vector: Theft of stored OAuth tokens from Klue’s integration service accounts.
    • Execution Method: Direct querying of Salesforce REST APIs using the stolen, valid tokens.
    • Security Bypass: The use of valid application-level tokens allowed attackers to circumvent MFA and traditional user-login-based security controls.
  • Threat Group Profile & Scale of Impact

    • Actor Identity: Icarus, an extortion-focused threat group.
    • Victim Profile: Multiple enterprises, including high-value targets like Managed Service Providers (MSPs) and cybersecurity firms.
    • Data Loss: Bulk exfiltration of sensitive customer records, sales pipelines, and enterprise contact information.
    • Exploitation Window: At least 24 hours of continuous, automated CRM data extraction.
  • Detection and Mitigation

    • Platform Action: Salesforce disabled the Klue Battlecards app integration on June 11, 2026, to halt the breach.
    • Detection Indicators: CRM access logs showing high-volume API calls originating from the Klue integration without corresponding user authentication events.
    • Active Threat: Ongoing extortion campaigns leveraging the stolen CRM intelligence.

Related posts

  1. reliaquest.com — Klue Integration Abused in Salesforce Data Theft
  2. SC Media — Icarus threat actors exploit Klue OAuth breach to steal Salesforce data
  3. techjacksolutions.com — Icarus Exploits Klue OAuth Chain to Exfiltrate Salesforce CRM Data Across Multiple Enterprises
  4. techjacksolutions.com — Salesforce Third-Party App Compromise Campaign Expands: Klue Battlecards Joins Growing Supply Chain Attack Series
  5. techjacksolutions.com — Salesforce Data Exfiltration via Klue OAuth Integration Compromise
  6. gbhackers.com — Hackers Exploit Klue Integration to Steal Salesforce CRM Data Using OAuth Tokens
  7. feeds.feedburner.com — Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
  8. helpnetsecurity.com — Klue breach lead to Salesforce data theft, Huntress affected
  9. Obsidiansecurity
  10. Status
  11. bleepingcomputer.com — Klue OAuth breach victim list grows as Icarus hackers claim attack
  12. Ampcuscyber
  13. Recordedfuture
  14. Rescana
  15. Tanium
  16. Dexpose
  17. Ghost-protocol
  18. Threatcodex
  19. techjacksolutions.com — Icarus Threat Actor Exploits Klue OAuth Tokens to Breach Multiple Salesforce Environments
  20. bleepingcomputer.com — LastPass confirms data breach in Klue supply chain attack
  21. techjacksolutions.com — Klue / Salesforce (Third-Party Integration) — Vulnerability Rollup (2026-06-26)
  22. Huntress
  23. Darkreading
  24. Salesforceben
  25. Kudelskisecurity
  26. Techechelon
  27. Govinfosecurity
  28. Radar
  29. Csidb
  30. Thecybersecguru
  31. Socdefenders
  32. News4Hackers — Salesforce Disables Klue Integration Over OAuth Token Theft Risk to Customer Data
  33. techjacksolutions.com — Salesforce — Vulnerability Rollup (2026-06-18)
  34. Aiweekly
  35. threatlocker.com — Klue: SaaS supply chain compromise through long-lived OAuth tokens
  36. threat-modeling.com — Icarus Threat Actor Expands Klue OAuth Breach with Salesforce Data Theft Attacks
  37. csoonline.com — Klue breach exposed Salesforce CRM data through stolen OAuth tokens
  38. fieldeffect.com — Klue integration breach exposes Salesforce customer data
  39. cybersecuritydive.com — Klue investigating supply chain attack that targeted Salesforce integrations
  40. Iansresearch
  41. App
  42. Rhisac
  43. Rodtrent
  44. Techradar
  45. Securitylabs
  46. Galaxywarden
  47. Obsidiansecurity
  48. Blog
  49. Klue
  50. Medium
  51. Youtube
  52. Hawk-eye
  53. Thenextweb
  54. Channelinsider
  55. Beazley
  56. Mashable
  57. Computing
  58. Reddit
  59. Pcmag
  60. Upguard
  61. Thenextweb
  62. Zscaler
  63. SecurityWeek — BeyondTrust, LastPass Impacted by Klue-Salesforce Incident
  64. SecurityWeek — More Klue Breach Victims Identified as Hackers Get Hacked

LINK COPIED TO CLIPBOARD