Klue OAuth Breach: Icarus Group Exfiltrates Salesforce Data
Market intelligence platform Klue has confirmed a major security breach where attackers stole OAuth tokens used to connect customer Salesforce environments, enabling unauthorized data exfiltration from multiple organizations.
The incident, claimed by the new “Icarus” extortion group, highlights how third-party integrations can become dangerous attack vectors. Consequently, businesses must evaluate OAuth token security and monitor integrations for unauthorized activity.
What Happened: Icarus Extortion Group Targets Klue OAuth Tokens
On June 12, 2026, Klue discovered unauthorized activity affecting its integration infrastructure. Also, cybersecurity firms Huntress and ReliaQuest independently investigated the incident and found attackers had compromised Klue Battlecards integrations.
Klue CEO Jason Smith confirmed the attackers used a compromised legacy credential to access integration services. Moreover, they obtained OAuth tokens connecting Klue with third-party platforms, primarily Salesforce. The attackers then accessed data within multiple connected customer environments.
The Icarus extortion group has publicly claimed responsibility for the attack. Therefore, organizations using Klue integrations should assume their data may have been exfiltrated until confirmed otherwise.
Technical Details of the OAuth Token Abuse
The attack exploited legacy credentials rather than a software vulnerability. ReliaQuest observed attackers generating OAuth tokens and using Python scripts to query Salesforce APIs for extended periods.
Huntress confirmed its own Salesforce environment was affected. The stolen data included business contacts, sales communications, pricing information, and other records. In addition, multiple victims have disclosed impacts, including Recorded Future, Tanium, Jamf, Sprout Social, and Gong.
The Icarus group posted on its data leak site, pressuring Klue and affected organizations to contact them via the Session messaging platform to prevent data leaks.
Affected Organizations Disclosed So Far
- Huntress — confirmed Salesforce data exfiltration
- Recorded Future — disclosed breach impact
- Tanium — published security advisory
- Jamf — confirmed affected by incident
- Sprout Social — posted customer notification
- Gong — acknowledged exposure
Business and Operational Impact
This breach demonstrates how third-party SaaS integrations create hidden supply chain risks. When threat actors compromise an integration platform, they can pivot into multiple customer environments simultaneously.
The impacts for affected organizations include:
- Exposed customer lists, pricing data, and sales communications
- Potential competitive intelligence loss
- Regulatory notification requirements under GDPR, CCPA, and state laws
- Reputational damage and customer trust erosion
- Extortion demands from the Icarus group
Moreover, the incident underscores how OAuth tokens, once stolen, bypass traditional authentication controls and enable persistent access until explicitly revoked.
Mitigation and Recommendations
Immediate Actions for Affected Organizations
- Revoke all Klue-related OAuth tokens in your identity provider
- Audit Salesforce login history for anomalous API access patterns
- Review OAuth application grants and remove unnecessary integrations
- Monitor for data exfiltration indicators in your environment
- Contact Klue for incident-specific guidance and support
Long-Term SaaS Integration Security
- Implement OAuth token expiration policies with short lifespans
- Use OAuth scopes to limit integration permissions to minimum required
- Enable continuous monitoring for unusual API activity
- Conduct regular third-party risk assessments on integration vendors
- Require MFA for all integration service accounts
Bottom line: Organizations must treat OAuth tokens as sensitive credentials. Therefore, they should monitor integration activity, enforce least-privilege access, and have rapid revocation procedures in place.
Incident Summary
| Incident: | Klue OAuth Token Breach by Icarus Extortion Group |
| Affected Platform: | Klue Market Intelligence — Salesforce integrations |
| Disclosure Date: | June 12, 2026 (discovered); June 19, 2026 (public confirmation) |
| Attack Vector: | Compromised legacy credential → OAuth token theft → API data exfiltration |
| Threat Actor: | Icarus extortion group |
| Known Victims: | Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong |
References
- BleepingComputer, “Klue OAuth breach victim list grows as Icarus hackers claim attack,” June 19, 2026, https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
- Klue CEO Jason Smith, “An Update on the Recent Klue Security Incident,” Klue Blog, June 2026, https://klue.com/blog/an-update-on-recent-klue-security-incident
- Huntress, “Klue Breach Investigation,” Huntress Blog, June 2026, https://www.huntress.com/blog/klue-breach-investigation
- ReliaQuest, “Threat Spotlight: Integration Abused in CRM Data Theft,” ReliaQuest Blog, June 2026, https://reliaquest.com/blog/threat-spotlight-integration-abused-in-crm-data-theft
- Recorded Future, “Klue Security Incident,” Recorded Future Blog, June 2026, https://www.recordedfuture.com/blog/klue-security-incident
- Tanium, “Security Update: Tanium’s Response to the Klue Breach,” Tanium Blog, June 2026, https://www.tanium.com/blog/security-update-taniums-response-to-the-klue-breach-that-allowed-data-exfiltration-from-salesforce/
- Jamf, “Klue Incident,” Jamf Blog, June 2026, https://www.jamf.com/blog/klue-incident/