logo

Salesforce Data Thefts Continue via Klue App Compromise

ID: 061dc9c4-b401-50be-88ec-4ccb84595d82

STIX ID: report--061dc9c4-b401-50be-88ec-4ccb84595d82

Feed Name: CosmicBytez Labs

Threat Score
80/100

Date Published: 2026-06-18

Date Updated: 2026-06-19

...
...

The report describes the Icarus campaign, where attackers compromise third-party SaaS apps (e.g., Klue Battlecards) and abuse long-lived, over-permissioned OAuth/API credentials to exfiltrate Salesforce CRM data across many customer organizations; Huntress is confirmed as a victim. The campaign demonstrates a high-impact SaaS-to-SaaS supply-chain risk and recommends OAuth token audits, least-privilege scopes, third-party security assessments, connected-app monitoring, and rapid token revocation runbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.