Klue Hack Exposes Salesforce Data Across Cybersecurity and Enterprise Customers


A breach at competitive intelligence vendor Klue has exposed Salesforce data from multiple customer environments, including several cybersecurity companies. The incident involved stolen OAuth tokens tied to Klue integrations, allowing attackers to access CRM records through trusted third-party connections.

Klue said it identified unauthorized activity on June 12, 2026, affecting part of its integration infrastructure. The company said an attacker gained access through a compromised legacy credential associated with an integration service.

Salesforce later disabled the Klue Battlecards app integration. In a Salesforce Trust Status message, the company said the activity may have resulted in unauthorized access to a subset of customer data through the app’s connection to Salesforce, and that the issue did not stem from a Salesforce platform vulnerability.

How the Klue Breach Happened

The incident centered on OAuth tokens, which allow SaaS tools to connect to customer environments without repeatedly asking for passwords or MFA codes. Once attackers obtained Klue-connected OAuth tokens, they could query customer CRM data as if they were the trusted Klue integration.

Huntress, one of the affected companies, said the attackers pushed a code update capable of collecting OAuth tokens used by Klue customers to connect Klue with their own systems. Huntress said the attackers then used those stolen credentials to query CRM tools directly and exfiltrate data.

Klue said it revoked affected credentials and tokens, removed unauthorized code, disabled potentially impacted integrations, opened a comprehensive investigation, and notified law enforcement. The company also engaged CrowdStrike to support the investigation.

Attackers Queried Salesforce Data at Scale

ReliaQuest said the adversary authenticated through a compromised Klue integration service account, generated OAuth tokens, and ran automated Python scripts against Salesforce REST API endpoints.

The activity included enumeration of Salesforce object catalogs and repeated queries against Salesforce data. ReliaQuest observed one burst of nearly 1,000 queries in 15 minutes, while another extraction window lasted more than six hours.

The exposed information varied by organization, but public notices generally point to CRM and business data. This includes names, work email addresses, job titles, phone numbers, business addresses, account records, opportunity notes, contract information, price quotes, and sales communications.

CompanyPublicly described impact
HuntressBusiness contacts, price quotes, sales-related data, and messaging. No products, infrastructure, telemetry, passwords, or payment card data were impacted.
Recorded FutureBusiness data fields in Salesforce, including client contact names, email addresses, and possible business contract information.
JamfSalesforce instance data accessed through Klue’s integration. Jamf said its products and customer service operations were not affected.
TaniumPublicly named among affected Klue customers in security industry reporting.
Gong, Insurity, Sprout SocialPublic notices cited Klue-related third-party exposure involving business or Salesforce-linked data.

Cybersecurity Companies Say Core Platforms Were Not Hit

Huntress said the copied Salesforce data included business contacts, price quotes, and other sales-related data. It said no threat data, passwords, payment card information, engineering data, agent data, or product telemetry were affected.

Recorded Future said its own investigation found the incident was limited to the third-party integration layer between Salesforce and Klue. The company said it found no evidence that its proprietary systems, internal databases, Intelligence Graph, or customer platform data were accessed.

Jamf said the incident occurred inside Klue’s environment and gave an unauthorized party access to Jamf’s Salesforce instance data through Klue’s integration. Jamf said the incident did not affect its products and did not affect its ability to serve customers.

Icarus Claims Responsibility

The extortion group Icarus has claimed responsibility for the Klue incident. Huntress said Klue appeared on the Icarus leak site on June 19, 2026, with the group claiming that Salesforce instances connected to Klue partners had been exfiltrated.

Huntress also said its employees received extortion emails warning that Salesforce data had been downloaded and giving the company 48 hours to respond. The company said it had high confidence in the attribution after matching indicators from its environment to Icarus infrastructure.

The case fits a wider pattern of attacks against SaaS integrations and non-human identities. These integrations often hold long-lived access to sensitive systems, but many organizations monitor them less closely than human user accounts.

Why OAuth Token Abuse Is So Dangerous

OAuth tokens can bypass the normal points where defenders expect to see suspicious logins. An attacker using a valid token may not need a password, an MFA prompt, or a new interactive login session.

That makes third-party SaaS integrations a high-value target. As Obsidian Security noted in its Klue analysis, Salesforce saw the activity as coming from the trusted Klue integration once the attacker held the token, even though the infrastructure did not match Klue’s normal footprint.

The breach also shows why SaaS supply chain attacks can spread quickly. A single compromised vendor integration can create access paths into many customer environments, especially when that integration connects to CRM, sales, marketing, support, file-sharing, or communications platforms.

What Klue and Customers Have Done

Klue said it disabled potentially affected integrations with third-party platforms while investigating the breach. Those integrations included Salesforce and other sales, marketing, collaboration, and communications tools.

Recorded Future said it locked down and revoked associated OAuth tokens connected to the Klue integration, worked with Salesforce for logs and support, reviewed Salesforce third-party applications, correlated malicious IP addresses, monitored for anomalies, and communicated with law enforcement.

Jamf said it disabled the Klue integration within Salesforce, found no evidence of lateral movement, contained the incident on its end, engaged cybersecurity experts, took defensive measures, and notified law enforcement.

  • Revoke OAuth tokens connected to Klue or other unused SaaS integrations.
  • Review Salesforce connected apps and remove stale authorizations.
  • Check API activity for unusual query volume, Python user-agent strings, and abnormal source infrastructure.
  • Review CRM exports, opportunity records, contact records, and contract-related data for signs of access.
  • Warn sales, customer success, and support teams about follow-on phishing risks.
  • Apply stricter monitoring to non-human identities and third-party SaaS integrations.

Salesforce Says It Was Not a Platform Vulnerability

The Salesforce Trust Status notice said Salesforce disabled the Klue Battlecards integration after detecting unusual activity involving the app. Salesforce said it continues to work with affected customers and Klue.

Klue said there is no evidence that customer content stored inside the Klue platform was impacted. The company described the event as a deliberate criminal act and said it is reviewing its security controls, credential management, monitoring, and deployment processes.

Security teams should treat this incident as a warning about SaaS integration hygiene. The biggest lesson is not only that CRM data is valuable, but that OAuth tokens and service accounts need the same scrutiny as administrator credentials.

How Organizations Can Reduce Similar Risk

Organizations that use Klue, Salesforce, or similar connected SaaS tools should conduct an immediate connected-app review. The goal is to identify which third-party applications have access, what scopes they hold, and whether each integration still serves a business purpose.

ReliaQuest recommended hunting for suspicious Salesforce REST API usage, abnormal query patterns, and integration activity from unexpected infrastructure. Security teams should also preserve logs quickly because some SaaS telemetry has limited retention windows.

Obsidian Security also recommends maintaining a full SaaS integration inventory, tracking OAuth scopes, and reviewing which users authorized each connected app. That advice applies beyond this incident because many SaaS tools rely on persistent tokens that can outlive the original business need.

FAQ

What happened in the Klue breach?

Attackers compromised part of Klue’s integration infrastructure through a legacy credential and obtained OAuth tokens used to connect Klue with customer SaaS platforms, including Salesforce.

Was Salesforce itself hacked?

Salesforce said the issue was limited to Klue’s app connection and did not arise from a vulnerability within the Salesforce platform.

What data was exposed in the Klue incident?

Public notices describe the exposed data mainly as Salesforce CRM and business information, including business contacts, email addresses, job titles, phone numbers, sales records, price quotes, contract details, and sales communications. Affected companies said core products, passwords, payment card data, and security telemetry were not impacted.

Who claimed responsibility for the Klue breach?

The extortion group Icarus claimed responsibility by listing Klue on its leak site. Huntress said it had high confidence in the attribution after matching indicators from its environment to Icarus infrastructure.

What should security teams do after the Klue breach?

Security teams should revoke Klue-related OAuth tokens where appropriate, review Salesforce connected apps, check API logs for unusual query volume, monitor for phishing using exposed CRM data, and audit other third-party SaaS integrations for stale permissions.

Readers help support VPNCentral. We may get a commission if you buy through our links. Tooltip Icon

Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more

User forum

0 messages