CSIDB logo
Incident

Sprout Social

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-08-12 01:06

Linked entities

Victim
Sprout Social
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2026
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Undetermined

Summary

A breach of business intelligence provider Klue allowed an unauthorized actor to exploit a compromised legacy credential, gain access to Klue’s integration infrastructure, and steal OAuth tokens used for its Battlecards app. The stolen tokens were used to impersonate Klue within connected Salesforce environments, enabling the exfiltration of customer data from several firms that used Klue’s services, including cybersecurity companies Huntress, Recorded Future, Jamf and Tanium, as well as non‑security firms such as Insurity and the social media analytics platform Sprout Social. Klue revoked the affected credentials and tokens, removed unauthorized code, disabled impacted integrations, notified law enforcement and engaged CrowdStrike for forensics. The intrusion was later claimed by the extortion group Icarus, which set a deadline for affected clients before threatening to release the stolen information.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 12, 2026, Klue detected an intrusion into its integration infrastructure, specifically the Klue Battlecards app, through a compromised legacy credential. The unauthorized actor obtained OAuth tokens from Klue and used them to connect Klue to third‑party platforms, including Salesforce. Using these tokens, the actor impersonated Klue within the connected Salesforce environments and exfiltrated sensitive customer information before the activity was detected and contained. Klue’s CEO Jason Smith announced the breach on June 19, stating that the company had revoked affected credentials and tokens, removed unauthorized code, disabled potentially impacted integrations, notified law enforcement, launched an internal investigation, and engaged CrowdStrike for forensic support.

Several cybersecurity firms that used Klue’s intelligence services—Huntress, Recorded Future, Jamf, and Tanium—confirmed that the breach enabled unauthorized access to their Salesforce accounts via the stolen OAuth tokens, while stating that their own products and services remained unaffected. Huntress warned that customer data such as business names, products trialed or used, subscription details, business contact information, and marketing and sales communications may have been compromised. Jamf advised customers to be vigilant against phishing campaigns that could leverage the stolen Salesforce data, noting that malicious actors might pose as Jamf employees. The breach also affected non‑cybersecurity organizations, including the insurance service provider Insurity and the social media analytics platform Sprout Social, which were listed among the Klue customers impacted by the incident.

Salesforce publicly notified users on June 17 that it had disabled the Klue Battlecards integration to prevent further unauthorized access. On June 19, the cyber extortion group Icarus claimed responsibility for the breach and posted that it had three victims on its data leak site according to Ransomware.live. On June 20, Icarus issued a deadline message to all Klue clients it claimed to have contacted, warning that they had until June 22 to respond before their data would be released. Klue stated that it continued to provide regular updates to customers and remediation guidance through various channels while its internal review and law‑enforcement cooperation proceeded.

Sources

Sources available to members: 1 source.

CSIDB