Hackers Breached Klue Integration to Steal Salesforce CRM Data via OAuth Tokens
ID: 1973e2e1-1c31-54e8-b62c-46a7ffc8fb02
STIX ID: report--1973e2e1-1c31-54e8-b62c-46a7ffc8fb02
Feed Name: cybersecurityNews.com
**Executive Summary:** ReliaQuest observed attackers abusing a compromised Klue Battlecards third‑party integration to harvest enterprise Salesforce CRM data by using stolen integration service‑account credentials to generate OAuth tokens and run automated REST API queries in a two‑phase pattern (long, stealthy enumeration followed by high‑volume bursts); Salesforce has disabled the Klue app pending investigation and ReliaQuest recommends immediate revocation/rotation of credentials and OAuth grants, auditing API logs for Python-urllib user-agents and unusual pagination/query volumes, and enforcing IP allowlisting. IP indicators observed include 138.226.246.94, 212.86.125.24, 213.111.148.90, and 94.154.32.160.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
