Recorded Future
Incident posture
Linked entities
- Victim
- Recorded Future
- Threat actors
- 2 actors
- Sources
- 4 sources
Timeline
Summary
Recorded Future reported that attackers exploited a compromised legacy credential in Klue’s integration infrastructure to steal OAuth tokens and access its Salesforce environment, exfiltrating business contact data such as names, email addresses, phone numbers, and sales-related information while confirming that threat data, passwords, payment card details, and engineering data remained unaffected. The company disabled the Klue integration, performed a forensic analysis, and highlighted the importance of monitoring third‑party connections; similar impacts were noted by other cybersecurity firms that also used Klue’s services, with attackers linked to the Icarus extortion group and Klue working with CrowdStrike to investigate and remediate the breach.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On June 12, 2026, Klue detected an intrusion into its systems after identifying a compromised legacy credential that granted access to its integration infrastructure, specifically the Klue Battlecards app. Using this access, the attacker obtained OAuth tokens for Klue’s integrations with third‑party platforms, including Salesforce, and used those tokens to impersonate Klue within connected Salesforce environments. The attacker then exfiltrated Klue customer data, including business contact information and sales‑related fields, over a period that included a concentrated burst of nearly a thousand Salesforce REST API queries in fifteen minutes and sustained extraction lasting over six hours. Klue responded by revoking the affected credentials and tokens, removing unauthorized code, and disabling potentially impacted integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack. Klue also notified law enforcement, launched an internal investigation, and engaged CrowdStrike to conduct forensic analysis. On June 17, Salesforce disabled the Klue Battlecards app integration after detecting unusual activity that may have resulted in unauthorized access to a subset of customer data. The intrusion was publicly attributed to the extortion group Icarus, which claimed responsibility on June 19 and set a deadline of June 22 for Klue clients to respond before threatening to release the stolen data.
Recorded Future confirmed that it was among the companies affected by the Klue‑Salesforce supply chain attack, stating that the impact was limited to business data fields in its Salesforce database such as client contact names and email addresses. The company disabled the Klue integration and performed a forensic analysis, emphasizing the need for continuous monitoring of third‑party integrations with privileged access to sensitive data. Huntress reported that data copied from its Salesforce account included business contacts, price quotes, and sales‑related data, but asserted that no threat data, passwords, payment card information, or engineering data were affected, while warning customers about possible phishing campaigns that could use the stolen Salesforce information. Jamf said it had no evidence of lateral movement and had contained the incident on its end, and Tanium reassured customers that there was no impact on its ability to serve them. LastPass notified its customers that hackers had obtained names, phone numbers, email addresses, physical addresses, customer support case records, and sales‑related data from Klue, although LastPass maintained that its own infrastructure, including password vaults, remained unaffected. Across the affected firms, the common response actions included disabling the Klue integration, conducting internal reviews, notifying customers, and advising vigilance against potential misuse of the exposed contact information.
Sources
Sources available to members: 4 sources.