Cyber Incident Victim: Jamf
Timeline
Summary
Jamf disclosed that a threat actor compromised legacy credentials of the market intelligence provider Klue, obtained OAuth tokens for its Salesforce integration, and accessed the company’s Salesforce environment, exfiltrating business contact information such as names, email addresses, job titles, phone numbers and business addresses. The company stated there was no evidence of lateral movement within its systems and that the incident was contained, while warning customers about potential phishing campaigns leveraging the stolen data.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
OnJune 11‑12, attackers gained access to Klue’s systems by exploiting a compromised legacy credential tied to the Klue Battlecards integration tool. This allowed them to obtain OAuth tokens used to connect Klue with Salesforce and other third‑party platforms. Using those tokens, the intruders accessed the Salesforce instances of multiple Klue customers and exfiltrated business information such as sales account data, names, email addresses, job titles, phone numbers and business addresses. Klue detected the intrusion on June 12 and publicly confirmed it on June 19 through a statement from CEO Jason Smith. Upon discovery, Klue revoked the affected credentials and tokens, removed unauthorized code and disabled the impacted integrations across its services. Klue engaged CrowdStrike to conduct forensic analysis and notified law‑enforcement agencies. Salesforce disabled the Klue Battlecards integration on June 17, and Gong disabled the same integration on the following Friday (June 21). The ransomware‑linked group Icarus claimed responsibility for the breach on June 19 and posted a threat on its leak site to release the stolen data unless Klue and the affected organizations entered negotiations. Icarus set a deadline of June 22 for a response, having previously listed three victims on its data‑leak site according to Ransomware.live. The attackers did not, according to Klue’s investigation, access or alter data stored within the Klue platform itself.

Jamf confirmed that it used Klue’s intelligence services and stated that its own systems showed no evidence of lateral movement, with the incident contained on its end. Jamf warned its customers that the stolen Salesforce data could be used in phishing campaigns and advised vigilance against messages purporting to be from Jamf employees. Huntress reported that customer data potentially exposed included business names, products trialed or used, subscription details, business contact information and marketing and sales communications. Recorded Future disabled the Klue integration, performed a forensic analysis and emphasized the need for continuous monitoring of third‑party integrations. Tanium told its customers that there was no impact on its ability to serve them. Other affected organizations such as HackerOne, OneTrust, Snyk and Insurity similarly notified their users that the breach was limited to Salesforce data and did not affect their core products. Sprout Social also informed its customers of the incident and confirmed that its own services remained unaffected. The exfiltrated information consisted primarily of business contact details—full names, email addresses, phone numbers, job titles and some account particulars—taken from the Salesforce CRMs of the compromised customers. No evidence was presented that the attackers modified or deleted any data within the victims’ Salesforce environments beyond the data they copied.
