Skip to content
The Cybersecurity Focus
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

The Cybersecurity Focus

Cybersecurity news, threat intelligence, and vulnerability research.

  • Home
  • Home
BreachIncidentVulnerability

Klue OAuth Breach: Icarus Group Exfiltrates Salesforce Data

By ogwatermelon
June 23, 2026 3 Min Read
0
June 22, 2026

Market intelligence platform Klue has confirmed a major security breach where attackers stole OAuth tokens used to connect customer Salesforce environments, enabling unauthorized data exfiltration from multiple organizations.

The incident, claimed by the new “Icarus” extortion group, highlights how third-party integrations can become dangerous attack vectors. Consequently, businesses must evaluate OAuth token security and monitor integrations for unauthorized activity.

What Happened: Icarus Extortion Group Targets Klue OAuth Tokens

On June 12, 2026, Klue discovered unauthorized activity affecting its integration infrastructure. Also, cybersecurity firms Huntress and ReliaQuest independently investigated the incident and found attackers had compromised Klue Battlecards integrations.

Klue CEO Jason Smith confirmed the attackers used a compromised legacy credential to access integration services. Moreover, they obtained OAuth tokens connecting Klue with third-party platforms, primarily Salesforce. The attackers then accessed data within multiple connected customer environments.

The Icarus extortion group has publicly claimed responsibility for the attack. Therefore, organizations using Klue integrations should assume their data may have been exfiltrated until confirmed otherwise.

Technical Details of the OAuth Token Abuse

The attack exploited legacy credentials rather than a software vulnerability. ReliaQuest observed attackers generating OAuth tokens and using Python scripts to query Salesforce APIs for extended periods.

Huntress confirmed its own Salesforce environment was affected. The stolen data included business contacts, sales communications, pricing information, and other records. In addition, multiple victims have disclosed impacts, including Recorded Future, Tanium, Jamf, Sprout Social, and Gong.

The Icarus group posted on its data leak site, pressuring Klue and affected organizations to contact them via the Session messaging platform to prevent data leaks.

Affected Organizations Disclosed So Far

  • Huntress — confirmed Salesforce data exfiltration
  • Recorded Future — disclosed breach impact
  • Tanium — published security advisory
  • Jamf — confirmed affected by incident
  • Sprout Social — posted customer notification
  • Gong — acknowledged exposure

Business and Operational Impact

This breach demonstrates how third-party SaaS integrations create hidden supply chain risks. When threat actors compromise an integration platform, they can pivot into multiple customer environments simultaneously.

The impacts for affected organizations include:

  • Exposed customer lists, pricing data, and sales communications
  • Potential competitive intelligence loss
  • Regulatory notification requirements under GDPR, CCPA, and state laws
  • Reputational damage and customer trust erosion
  • Extortion demands from the Icarus group

Moreover, the incident underscores how OAuth tokens, once stolen, bypass traditional authentication controls and enable persistent access until explicitly revoked.

Mitigation and Recommendations

Immediate Actions for Affected Organizations

  1. Revoke all Klue-related OAuth tokens in your identity provider
  2. Audit Salesforce login history for anomalous API access patterns
  3. Review OAuth application grants and remove unnecessary integrations
  4. Monitor for data exfiltration indicators in your environment
  5. Contact Klue for incident-specific guidance and support

Long-Term SaaS Integration Security

  • Implement OAuth token expiration policies with short lifespans
  • Use OAuth scopes to limit integration permissions to minimum required
  • Enable continuous monitoring for unusual API activity
  • Conduct regular third-party risk assessments on integration vendors
  • Require MFA for all integration service accounts

Bottom line: Organizations must treat OAuth tokens as sensitive credentials. Therefore, they should monitor integration activity, enforce least-privilege access, and have rapid revocation procedures in place.

Incident Summary

Incident: Klue OAuth Token Breach by Icarus Extortion Group
Affected Platform: Klue Market Intelligence — Salesforce integrations
Disclosure Date: June 12, 2026 (discovered); June 19, 2026 (public confirmation)
Attack Vector: Compromised legacy credential → OAuth token theft → API data exfiltration
Threat Actor: Icarus extortion group
Known Victims: Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong

References

  1. BleepingComputer, “Klue OAuth breach victim list grows as Icarus hackers claim attack,” June 19, 2026, https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
  2. Klue CEO Jason Smith, “An Update on the Recent Klue Security Incident,” Klue Blog, June 2026, https://klue.com/blog/an-update-on-recent-klue-security-incident
  3. Huntress, “Klue Breach Investigation,” Huntress Blog, June 2026, https://www.huntress.com/blog/klue-breach-investigation
  4. ReliaQuest, “Threat Spotlight: Integration Abused in CRM Data Theft,” ReliaQuest Blog, June 2026, https://reliaquest.com/blog/threat-spotlight-integration-abused-in-crm-data-theft
  5. Recorded Future, “Klue Security Incident,” Recorded Future Blog, June 2026, https://www.recordedfuture.com/blog/klue-security-incident
  6. Tanium, “Security Update: Tanium’s Response to the Klue Breach,” Tanium Blog, June 2026, https://www.tanium.com/blog/security-update-taniums-response-to-the-klue-breach-that-allowed-data-exfiltration-from-salesforce/
  7. Jamf, “Klue Incident,” Jamf Blog, June 2026, https://www.jamf.com/blog/klue-incident/

Tags:

BreachIncident
Author

ogwatermelon

Follow Me
Other Articles
Previous

AryStinger Botnet Hijacks 4,300 D-Link Routers for Global Proxy Network

Next

Squidbleed CVE-2026-47729: 29-Year Squid Proxy Bug Leaks HTTP Credentials

AI Botnet Breach CVE Exploit Hack Incident Linux Malware Network Ransomware supply chain Vulnerability Windows World Zero Day

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Archives

  • July 2026
  • June 2026
  • May 2026

Categories

  • AI
  • BotNet
  • Breach
  • CVE
  • exploit
  • Hack
  • Incident
  • Linux
  • Malware
  • Phishing
  • Ransomware
  • supply-chain
  • Uncategorized
  • Vulnerability
  • Windows
  • World
  • Zero Day
Copyright 2026 — The Cybersecurity Focus. All rights reserved.