CSIDB logo
Incident

Huntress

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-26 22:09

Linked entities

Victim
Huntress
Threat actors
2 actors
Sources
5 sources

Timeline

Occurred
Jun 2026
Discovered
Jun 2026
Disclosed
Jun 2026
Resolved
Pending

Summary

Attackers compromised the Klue platform, obtained OAuth tokens for its Salesforce integration, and used them to access the Salesforce instances of multiple customers, including the cybersecurity vendor Huntress. The exfiltrated data consisted of business contact information, sales‑related communications, subscription details and product trial data, while no passwords, payment card information, or internal product data were affected. The intrusion was confined to the Salesforce environments, with no evidence of lateral movement into the victims’ own systems. An extortion group claiming responsibility posted portions of the stolen data on a leak site and threatened further release unless demands were met. Salesforce subsequently disabled the compromised Klue integration, and the affected organizations confirmed that their core services remained operational.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 11, attackers pushed a code update to Klue’s environment in order to collect OAuth tokens, using a long‑disused but active credential to gain access. They compromised Klue’s integration infrastructure, notably the Klue Battlecards app, and obtained OAuth tokens that allowed them to connect to third‑party platforms including Salesforce. Using the stolen tokens, the attackers abused the Salesforce REST API to exfiltrate large volumes of CRM data over a 24‑hour window, which included a concentrated burst of nearly a thousand queries in fifteen minutes and sustained extraction periods lasting more than six hours. Klue detected the intrusion on June 12, revoked the affected credentials and tokens, disabled the integrations across multiple services, notified law enforcement and began an investigation with CrowdStrike. Salesforce announced on June 17 that it had disabled the Klue Battlecards integration after detecting unusual activity that may have resulted in unauthorized access to a subset of customer data. Huntress was the first company to publicly acknowledge that its Salesforce data had been compromised in the incident.

The data taken from Huntress’s Salesforce instance comprised business contact information such as full names, work emails, job titles, phone numbers and business addresses, as well as business names, products trialed or used, subscription details (units and pricing), sales‑related communications including price quotes, contacts and tasks, and opportunity notes that contain free‑form fields for tracking thoughts and next steps. Huntress confirmed that no threat data, passwords, payment card information, engineering data, infrastructure data or telemetry was accessed. Other organizations that disclosed impact included LastPass, Gong, HackerOne, Jamf, OneTrust, Recorded Future, Snyk, Tanium, Insurity and Sprout Social. Gong reported that attackers may have accessed internal licensed user data for a subset of its customers, specifically usernames, user business titles and user emails. The extortion group Icarus claimed responsibility, posted data on a Tor‑based leak site and set a deadline of June 22 for Klue customers to negotiate before the information would be released. Huntress confirmed that the data posted by Icarus matched the scope determined by its own investigation and warned that the primary risk posed by the compromise was threat actors using the stolen information to craft targeted social engineering messages.

Klue revoked the compromised credentials and tokens, disabled the affected integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack, and engaged CrowdStrike to support forensic analysis while stating there was no evidence that customer content stored within the Klue platform was impacted. Salesforce’s disabling of the Klue Battlecards integration on June 17 prevented further OAuth token misuse. Huntress reported that its own products, services, infrastructure, telemetry, passwords and payment card information remained unaffected. Recorded Future disabled the Klue integration and conducted a forensic analysis, emphasizing the need for continuous monitoring of third‑party integrations. Tanium told customers that there was no impact on its ability to serve them. Jamf noted that it had no evidence of lateral movement and had contained the incident on its end, while advising vigilance against possible phishing campaigns that could use the stolen Salesforce data. Huntress issued a statement advising recipients to verify any incident‑related messages through known channels only and to confirm requests out‑of‑band before transferring funds or handing over credentials.

Sources

Sources available to members: 5 sources.

CSIDB