Menu
Browse

Cyber Incident Victim: Recorded Future

Date

Jun 2026

Location

United States of America

Status

Unknown

Updated

2026-07-17 00:38

Timeline
Occurred
Jun 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

Attackers compromised the Klue market intelligence platform’s backend, executed unauthorized commands and pushed a code update that harvested OAuth tokens for customers’ integrations, then used the Salesforce REST API to extract large volumes of CRM data over a sustained period. Huntress and Recorded Future confirmed they were among the affected companies, with attackers copying business contact fields such as names and email addresses while no threat data, passwords, payment card information or engineering data was taken. The platform responded by deactivating OAuth tokens for all customers and disabling integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack, and Salesforce subsequently disabled the Battlecards app integration after detecting unusual activity. The attackers later attempted extortion, linking the activity to a threat actor known as Mr Brean associated with the Icarus group.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
2 actors Available to members Available to members

Description

On June 11 2026 threat actors gained unauthorized access to Klue’s backend servers and executed unauthorized commands that pushed a code update designed to harvest OAuth tokens for customers’ Klue integrations. Klue became aware of the compromise and notified its customers on June 12, informing them that it had deactivated OAuth tokens for all customers and disabled integrations with a range of third‑party platforms including Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack. The notification explained that the malicious code was intended to exfiltrate OAuth tokens that could be used to access customer data stored in those connected services.

Cyber Incident Image

According to analysis by ReliaQuest, the attackers abused the Salesforce REST API to exfiltrate large volumes of customer relationship management data over a roughly 24‑hour window. This exfiltration included a concentrated burst of nearly a thousand queries within a 15‑minute period and sustained extraction periods lasting more than six hours. Huntress confirmed that data copied from its Salesforce instance included business contacts, price quotes and sales‑related information, but emphasized that no threat data, passwords, payment card details or engineering data were compromised. Recorded Future reported that the impact was limited to business data fields in its Salesforce database, specifically client contact names and email addresses, and confirmed that its internal systems were not accessed by the attackers.

In response to the incident, Klue disabled the affected integrations and revoked the compromised OAuth tokens. On June 17 Salesforce disabled the Klue Battlecards app integration after detecting unusual activity that could have led to unauthorized access to a subset of customer data via the app’s connection to Salesforce. Huntress reported receiving extortion attempts from a threat actor identifying himself as “Mr Brean,” who is linked to the Icarus group; Icarus’ leak site displayed data allegedly stolen from Salesforce, which Huntress cited as supporting the attribution. The attack follows patterns seen in earlier Salesforce, Salesloft Drift and Gainsight incidents that have been attributed to the ShinyHunters and UNC6395 threat clusters, although SecurityWeek notes that the current activity appears to involve a previously unidentified threat actor. Klue has not issued a public statement about the breach, and SecurityWeek has requested comment from the company.

The incident resulted in the exposure of business contact information and sales‑related data for Huntress and Recorded Future, while no sensitive credentials, payment information or proprietary engineering data were taken, and the attackers did not gain direct access to the victims’ internal networks beyond the Klue‑Salesforce integration. The coordinated response involved token revocation, integration shutdowns, platform‑level app disabling by Salesforce, and public disclosure by the affected security firms. This concludes the factual account of the Klue supply chain attack as described in the available sources.

Sources
Sources available to members
4 sources