CSIDB logo
Incident

OneTrust

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-11 05:48

Linked entities

Victim
OneTrust
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2026
Discovered
Undetermined
Disclosed
Jun 2026
Resolved
Pending

Summary

Attackers used compromised legacy credentials to gain access to Klue’s systems and obtain OAuth tokens for its Salesforce integration, allowing them to reach the Salesforce environments of several Klue customers. Among those customers were HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk, Tanium, Insurity and Sprout Social, from which the intruders exfiltrated business information such as names, email addresses, job titles, phone numbers and addresses. Klue revoked the affected credentials and tokens, disabled the integrations, and worked with CrowdStrike and law enforcement to investigate. Huntress suggested that a threat actor known as Icarus might be behind the breach, and Icarus later claimed responsibility on a Tor‑based leak site, threatening to release the stolen data unless negotiations occurred.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 11-12, attackers used compromised legacy credentials to gain access to Klue's systems. They obtained OAuth tokens used to connect Klue with Salesforce and subsequently accessed data within a number of connected customer environments, including OneTrust's Salesforce instance. Klue confirmed the breach, revoked the affected credentials and tokens, disabled the integrations across multiple services, and began investigating the attack together with CrowdStrike and law enforcement.

The intrusion was limited to the Salesforce instances of the affected customers and did not involve their internal systems or the Klue platform itself. Exfiltrated data consisted of business information from the Salesforce CRMs, including sales account data and business contact information such as names, email addresses, job titles, phone numbers, and business addresses. OneTrust, along with HackerOne, Huntress, Jamf, Recorded Future, Snyk, Tanium, Insurity, and Sprout Social, publicly acknowledged the impact of the incident. Salesforce disabled the Klue integration in response to the breach, and the revenue intelligence platform Gong also disabled its Klue integration after warning that the hackers had exploited the connection to access internal licensed user data. Klue stated that, based on its investigation to date, there was no evidence that customer content stored within the Klue platform was impacted.

Huntress suggested in its analysis that a threat actor named Icarus might have been responsible for the attack. Subsequently, Icarus added Klue to its Tor-based leak site, claiming responsibility for the intrusion and threatening to publish the information stolen from Klue customers’ Salesforce instances. According to the threat actor’s posts, the data would be released on June 22 unless Klue and the affected organizations engaged in negotiations.

Sources

Sources available to members: 1 source.

CSIDB