OneTrust
Incident posture
Timeline
Summary
Attackers used compromised legacy credentials to gain access to Klue’s systems and obtain OAuth tokens for its Salesforce integration, allowing them to reach the Salesforce environments of several Klue customers. Among those customers were HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, Tanium, Insurity and Sprout Social, from which the intruders exfiltrated business information such as names, email addresses, job titles, phone numbers and addresses. Klue revoked the affected credentials and tokens, disabled the integrations, and worked with CrowdStrike and law enforcement to investigate. Huntress suggested that a threat actor known as Icarus might be behind the breach, and Icarus later claimed responsibility on a Tor‑based leak site, threatening to release the stolen data unless negotiations occurred.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On June 11-12, attackers used compromised legacy credentials to gain access to Klue's systems. They obtained OAuth tokens used to connect Klue with Salesforce and subsequently accessed data within a number of connected customer environments, including OneTrust's Salesforce instance. Klue confirmed the breach, revoked the affected credentials and tokens, disabled the integrations across multiple services, and began investigating the attack together with CrowdStrike and law enforcement.
The intrusion was limited to the Salesforce instances of the affected customers and did not involve their internal systems or the Klue platform itself. Exfiltrated data consisted of business information from the Salesforce CRMs, including sales account data and business contact information such as names, email addresses, job titles, phone numbers, and business addresses. OneTrust, along with HackerOne, Huntress, Jamf, Recorded Future, Snyk, Tanium, Insurity, and Sprout Social, publicly acknowledged the impact of the incident. Salesforce disabled the Klue integration in response to the breach, and the revenue intelligence platform Gong also disabled its Klue integration after warning that the hackers had exploited the connection to access internal licensed user data. Klue stated that, based on its investigation to date, there was no evidence that customer content stored within the Klue platform was impacted.
Huntress suggested in its analysis that a threat actor named Icarus might have been responsible for the attack. Subsequently, Icarus added Klue to its Tor-based leak site, claiming responsibility for the intrusion and threatening to publish the information stolen from Klue customers’ Salesforce instances. According to the threat actor’s posts, the data would be released on June 22 unless Klue and the affected organizations engaged in negotiations.
Sources
Sources available to members: 1 source.