Menu
Browse

Cyber Incident Victim: Huntress

Date

Jun 2026

Location

United States of America

Status

Unknown

Updated

2026-07-16 01:20

Timeline
Occurred
Jun 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending
Summary

A supply chain compromise of the Klue Battlecards application allowed attackers to push a malicious update that harvested OAuth tokens for customers’ Klue integrations, which were then used via the Salesforce REST API to exfiltrate customer relationship management data, including business contacts and sales‑related information, while no threat data, passwords, payment card details or engineering data were taken; the attackers generated a concentrated burst of nearly a thousand queries in a short period and sustained extraction over several hours. Klue responded by deactivating all OAuth tokens and disabling integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive and Slack, and Salesforce subsequently suspended the Klue Battlecards app after detecting unusual activity. Huntress disclosed that its Salesforce data included business contacts and sales details and reported extortion attempts from a threat actor linked to the Icarus group, while Recorded Future noted the impact was limited to business data fields such as client contact names and email addresses.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
2 actors Available to members Available to members

Description

OnJune 11, 2026, attackers pushed a code update to Klue’s backend that harvested OAuth tokens for customers’ Klue integrations. Klue notified customers on June 12, deactivated OAuth tokens for all customers and disabled integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack. On June 17, Salesforce detected unusual activity involving the Klue Battlecards app and suspended the integration, warning of possible unauthorized access to a subset of customer data via the app’s connection to Salesforce. Huntress and Recorded Future disclosed they were affected by the supply chain attack.

Cyber Incident Image

Huntress reported that data copied from its Salesforce instance included business contacts, price quotes, and sales‑related data, but no threat data, passwords, payment card information, or engineering data was exfiltrated. Recorded Future stated the impact was limited to business data fields in its Salesforce database, specifically client contact names and email addresses, with no threat data, passwords, payment card, or engineering data compromised. Huntress also said it received extortion attempts from a threat actor identifying himself as “Mr Brean,” who is linked to the Icarus group, and the Icarus leak site displayed data allegedly stolen from Salesforce supporting the attribution.

Klue deactivated OAuth tokens for all customers and disabled the listed integrations on June 12. Salesforce disabled the Klue Battlecards app integration on June 17 after detecting the unusual activity. Huntress and Recorded Future publicly disclosed the scope of the data accessed. Huntress disclosed the extortion attempt and confirmed that no threat data, passwords, payment card, or engineering data were taken. Recorded Future confirmed the limitation of the exposed data to client contact names and email addresses.

The attack follows patterns seen in prior Salesforce, Salesloft Drift, and Gainsight incidents that have been attributed to ShinyHunters and UNC6395. However, the activity appears to involve a new threat actor according to SecurityWeek reporting. Klue has not publicly disclosed technical details of the breach. SecurityWeek has requested a statement from the company regarding the incident.

Sources
Sources available to members
5 sources