Insurity
Incident posture
Timeline
Summary
A hacking group compromised a legacy credential used by Klue to access its integration infrastructure, allowing them to steal OAuth tokens and impersonate the service inside customers' Salesforce environments. The attackers exfiltrated business contact information and related data from multiple organizations, including several cybersecurity firms and the insurance provider Insurity. The group, identifying itself as Icarus, claimed responsibility and threatened to publish the stolen data unless a ransom was paid. Klue responded by revoking the compromised credentials and tokens, disabling affected integrations, notifying law enforcement, and engaging CrowdStrike for forensic analysis. Affected companies confirmed the breach, warned of potential phishing attempts leveraging the stolen information, and took steps to secure their own systems.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On June 12 2026 Klue detected an intrusion into its integration infrastructure, specifically the Klue Battlecards app, after an unauthorized actor gained access using a compromised legacy credential such as a password or token associated with a customer‑data integration tool. The actor used this access to harvest OAuth tokens that Klue employs to connect with third‑party platforms, notably Salesforce, and then impersonated Klue within those customer environments to exfiltrate data from linked cloud databases. Klue’s CEO Jason Smith issued an official statement on June 19 confirming the June 12 detection date and describing how the attacker leveraged the stolen tokens to reach customer Salesforce accounts before the activity was contained. The breach was publicly claimed on June 19 by the extortion group Icarus, which posted a leak site and, on June 20, issued a deadline to Klue‑affiliated customers demanding a response by June 22 lest the stolen data be released.
The compromised data included business contact information such as names, email addresses, phone numbers, job titles and some account details, as well as additional fields like business names, products trialed or used, subscription details and marketing and sales communications, according to warnings from affected firms Huntress and Jamf. Companies that confirmed exposure were Huntress, Recorded Future, Jamf, Tanium, Insurity, Sprout Social, Gong, OneTrust, Snyk and others noted in the reporting. Huntress noted that customer data may have been compromised, while Jamf warned of possible phishing campaigns leveraging the stolen Salesforce records and stated there was no evidence of lateral movement on its systems. Recorded Future disabled the Klue integration and performed a forensic analysis, and Tanium assured customers that its ability to serve them was unaffected.
In response, Klue revoked the affected credentials and tokens, removed unauthorized code, disabled potentially impacted integrations, notified law enforcement, launched an internal investigation and engaged CrowdStrike for forensic support. Salesforce announced on June 17 that it had disabled the Klue Battlecards integration to prevent further abuse. Affected customers applied their own mitigations: Huntress, Recorded Future, Jamf and Tanium each disclosed the incident in blog posts, disabled the Klue integration, conducted internal reviews and advised customers to remain vigilant against phishing attempts using the exposed data. Klue’s CEO Jason Smith did not respond to a request for comment from TechCrunch, and the company noted that it does not currently list a dedicated cybersecurity officer on its executive leadership page. Additionally, Klue had previously announced plans to lay off roughly half of its staff—about 100 employees—in June 2025 as it shifted focus to AI investments, though the article notes it is unclear whether that staffing change contributed to security gaps.
Sources
Sources available to members: 2 sources.