CSIDB logo
Incident

Recorded Future

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-16 00:50

Linked entities

Victim
Recorded Future
Threat actors
2 actors
Sources
4 sources

Timeline

Occurred
Jun 2026
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Pending

Summary

Recorded Future reported that attackers exploited a compromised legacy credential in Klue’s integration infrastructure to steal OAuth tokens and access its Salesforce environment, exfiltrating business contact data such as names, email addresses, phone numbers, and sales-related information while confirming that threat data, passwords, payment card details, and engineering data remained unaffected. The company disabled the Klue integration, performed a forensic analysis, and highlighted the importance of monitoring third‑party connections; similar impacts were noted by other cybersecurity firms that also used Klue’s services, with attackers linked to the Icarus extortion group and Klue working with CrowdStrike to investigate and remediate the breach.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On June 12, 2026, Klue detected an intrusion into its systems after identifying a compromised legacy credential that granted access to its integration infrastructure, specifically the Klue Battlecards app. Using this access, the attacker obtained OAuth tokens for Klue’s integrations with third‑party platforms, including Salesforce, and used those tokens to impersonate Klue within connected Salesforce environments. The attacker then exfiltrated Klue customer data, including business contact information and sales‑related fields, over a period that included a concentrated burst of nearly a thousand Salesforce REST API queries in fifteen minutes and sustained extraction lasting over six hours. Klue responded by revoking the affected credentials and tokens, removing unauthorized code, and disabling potentially impacted integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack. Klue also notified law enforcement, launched an internal investigation, and engaged CrowdStrike to conduct forensic analysis. On June 17, Salesforce disabled the Klue Battlecards app integration after detecting unusual activity that may have resulted in unauthorized access to a subset of customer data. The intrusion was publicly attributed to the extortion group Icarus, which claimed responsibility on June 19 and set a deadline of June 22 for Klue clients to respond before threatening to release the stolen data.

Recorded Future confirmed that it was among the companies affected by the Klue‑Salesforce supply chain attack, stating that the impact was limited to business data fields in its Salesforce database such as client contact names and email addresses. The company disabled the Klue integration and performed a forensic analysis, emphasizing the need for continuous monitoring of third‑party integrations with privileged access to sensitive data. Huntress reported that data copied from its Salesforce account included business contacts, price quotes, and sales‑related data, but asserted that no threat data, passwords, payment card information, or engineering data were affected, while warning customers about possible phishing campaigns that could use the stolen Salesforce information. Jamf said it had no evidence of lateral movement and had contained the incident on its end, and Tanium reassured customers that there was no impact on its ability to serve them. LastPass notified its customers that hackers had obtained names, phone numbers, email addresses, physical addresses, customer support case records, and sales‑related data from Klue, although LastPass maintained that its own infrastructure, including password vaults, remained unaffected. Across the affected firms, the common response actions included disabling the Klue integration, conducting internal reviews, notifying customers, and advising vigilance against potential misuse of the exposed contact information.

Sources

Sources available to members: 4 sources.

CSIDB