logo

Hackers Breached Klue Integration to Steal Salesforce CRM Data via OAuth Tokens

ID: 1973e2e1-1c31-54e8-b62c-46a7ffc8fb02

STIX ID: report--1973e2e1-1c31-54e8-b62c-46a7ffc8fb02

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Guru Baran

...
...

**Executive Summary:** ReliaQuest observed attackers abusing a compromised Klue Battlecards third‑party integration to harvest enterprise Salesforce CRM data by using stolen integration service‑account credentials to generate OAuth tokens and run automated REST API queries in a two‑phase pattern (long, stealthy enumeration followed by high‑volume bursts); Salesforce has disabled the Klue app pending investigation and ReliaQuest recommends immediate revocation/rotation of credentials and OAuth grants, auditing API logs for Python-urllib user-agents and unusual pagination/query volumes, and enforcing IP allowlisting. IP indicators observed include 138.226.246.94, 212.86.125.24, 213.111.148.90, and 94.154.32.160.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.