logo

Klue OAuth Breach Victim List Grows as Icarus Hackers Claim Attack

ID: 39bb41e6-b39b-588f-b089-d317d9ba19b2

STIX ID: report--39bb41e6-b39b-588f-b089-d317d9ba19b2

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-06-19

Date Updated: 2026-06-20

...
...

**Executive summary:** Klue, a competitive intelligence SaaS, confirmed that attackers stole OAuth tokens used to access customers' Salesforce instances; the Icarus extortion group claims responsibility and the incident is part of a broader campaign targeting SaaS-to-Salesforce integrations, risking wide-scale CRM data exposure — revoke tokens, audit connected apps, enable event monitoring, and implement a third-party breach runbook.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.