Menu
Browse

Cyber Incident Victim: Klue

Date

Jun 2026

Location

United States of America

Status

Unknown

Updated

2026-07-27 20:27

Timeline
Occurred
Jun 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

A supply chain breach of Klue occurred when attackers exploited a legacy credential in its integration infrastructure to deploy code that harvested OAuth tokens from customers, enabling them to impersonate the provider and access connected Salesforce environments. The attackers harvested business contact and sales data from dozens of the provider’s customers, including cybersecurity firms such as Huntress, Recorded Future, Tanium, Jamf, HackerOne, Snyk, OneTrust and Gong, then attempted extortion via a Tor‑based leak site operated by the threat actor Icarus. After the initial extortion attempt, a second unauthorized party compromised Icarus, obtained the same stolen data and launched a separate extortion campaign. No ransomware, destructive malware or engineering data was compromised, and the breach was limited to the provider’s Salesforce integration and associated customer data.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
2 actors Available to members Available to members

Description

Between June 11 and June 24 2026 a threat actor identified as Icarus exploited a long‑disused but still active credential within Klue’s integration infrastructure to gain initial access. Using that credential the attackers pushed a code update that harvested OAuth tokens from Klue’s customers, allowing them to impersonate Klue and connect to downstream Salesforce environments. The harvested tokens were then used with legitimate cloud APIs, including the Salesforce REST API, to execute a series of queries that exfiltrated business contact and sales data over a 24‑hour window, including a burst of nearly a thousand queries in fifteen minutes and sustained extraction lasting over six hours. The attackers employed MITRE ATT&CK techniques T1078 (valid accounts), T1528 (steal application access tokens), T1550 (use alternate authentication material), T1213 (data from information repositories) and T1567.002 (exfiltration over web services) before posting the stolen data on a Tor‑based leak site and demanding payment via extortion emails sent from compromised infrastructure belonging to the Australian retailer “Global Retail Brands,” with the leak site hosted on AS200593 (PROSPERO OOO, Russian Federation).

Cyber Incident Image

The breach affected dozens of Klue customers, including the cybersecurity firms Huntress, Recorded Future, Tanium, Jamf, HackerOne, Snyk, OneTrust, Insurity, Sprout Social and the revenue intelligence platform Gong, as well as other SaaS customers. Exfiltrated data consisted primarily of business contact information such as full names, email addresses, phone numbers, job titles and business addresses, along with sales account data and price quotes. Affected organizations confirmed that the intrusion was limited to their Salesforce instances and that no threat data, passwords, payment card information or engineering data was compromised. Huntress and Recorded Future specifically noted that the accessed data comprised client contact names, email addresses and related sales fields, with no impact on their core threat intelligence or engineering systems.

In response, Klue notified affected customers on June 12, deactivated all OAuth tokens and disabled integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack. Klue engaged the cybersecurity firm CrowdStrike to investigate the incident and retained external advisors for incident response. Salesforce disabled the Klue Battlecards app integration on June 17 after detecting anomalous activity linked to the app’s connection to Salesforce. Gong likewise disabled its Klue integration and warned that the attackers may have accessed internal licensed user data such as user names, business titles and email addresses, while confirming no effect on call recordings or customer transcripts. Huntress reported receiving extortion attempts from a threat actor known as “Mr Brean,” which was linked to the Icarus group, and Recorded Future corroborated that the impact was confined to business data fields in their Salesforce database.

A second unauthorized party subsequently obtained the same stolen data and launched an independent extortion campaign, indicating that the initial attackers had themselves been compromised. No evidence of ransomware deployment, destructive activity or advanced persistent threat involvement was found in any of the sources reviewed. Indicators of compromise shared by Huntress on June 18 2026 included the IP addresses 138.226.246.94, 212.86.125.24, 213.111.148.90 and 94.154.32.160. As of the latest reporting on June 26 2026, no public patches or fixes for the Klue‑Salesforce integration had been released, and affected organizations were advised by Klue to monitor communications, verify potential exposure and coordinate with legal counsel and law enforcement as needed. The incident highlighted the risks inherent in third‑party SaaS integrations and the use of legacy credentials in supply‑chain attacks.

Sources
Sources available to members
8 sources