Klue OAuth Breach: Icarus Steals Salesforce CRM Data from Huntress, Tanium, Recorded Future and Hundreds More
How threat group Icarus weaponized Klue OAuth app tokens to silently extract Salesforce data across hundreds of security vendors.
This post is part of the Week of June 26, 2026 Security Roundup.
Overview
Market intelligence platform Klue suffered an OAuth integration breach beginning June 11, 2026, enabling the threat group Icarus to steal Salesforce CRM data from hundreds of downstream organizations. Victims confirmed to date include: Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong, HackerOne, OneTrust, and Insurity. Icarus publicly claimed the attack on June 19, 2026. Salesforce has since disabled the Klue Battlecards integration on its platform.
Attack Chain
- Initial Access (June 11): Attacker used a long-dormant but still-active credential originally created by Klue for a prototype third-party integration that was later abandoned — a classic case of stale credential sprawl.
- Lateral Movement: Using that credential, the attacker pivoted into Klue's integration infrastructure and harvested OAuth tokens that connected Klue's Battlecards product to customer Salesforce environments.
- Data Exfiltration: The stolen OAuth tokens were used to query victim Salesforce instances directly. Data exfiltrated includes: customer names, business email addresses, phone numbers, job titles, sales notes, CRM records, pricing information and quotes, and internal sales communications.
- Extortion (June 19+): Icarus began directly contacting affected organizations with extortion demands, and published victim lists on its dark web portal.
Root Cause: Stale Credential Sprawl
The root cause is a textbook example of abandoned integration credential persistence. Klue created a service credential for a prototype integration, then discontinued the integration without revoking the credential. The credential remained valid and scoped with the access it was granted years earlier. This pattern is extremely common in organizations using SaaS platforms with OAuth integrations — each new integration creates credentials, and decommissioned integrations rarely trigger a credential revocation workflow.
IOCs
- Threat group: Icarus (active since April 28, 2026)
- Initial access date: June 11, 2026
- Extortion claims published: June 19, 2026
- Salesforce integration disabled: ~June 22, 2026
Affected Organizations (Confirmed)
Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong, HackerOne, OneTrust, Insurity — and reportedly "hundreds" of additional Klue customers per The Register. Security firms being among the victims adds irony and illustrates that supply chain OAuth attacks are indiscriminate.
Remediation
- Immediate (if you are a Klue customer): Assume your Salesforce CRM data has been exfiltrated. Notify affected individuals per applicable breach disclosure laws. Monitor for targeted phishing using the stolen contact data.
- Audit all OAuth integrations: Enumerate every OAuth app connected to your Salesforce org via Setup → Connected Apps OAuth Usage. Revoke any app you do not actively use.
- Enforce integration hygiene: Implement a process to revoke credentials and OAuth grants when SaaS integrations are decommissioned.
- Least-privilege OAuth scopes: Review what scopes each connected app has been granted. Most integrations require far fewer permissions than they are given.
- Monitor Salesforce API activity: Enable Salesforce Shield Event Monitoring or equivalent to alert on unusual bulk-query patterns from third-party integrations.
- Rotate Salesforce credentials and session tokens for all affected organizations.