Klue OAuth Breach Victim List Grows as Icarus Hackers Claim Attack
ID: 39bb41e6-b39b-588f-b089-d317d9ba19b2
STIX ID: report--39bb41e6-b39b-588f-b089-d317d9ba19b2
Feed Name: CosmicBytez Labs
Threat Score
**Executive summary:** Klue, a competitive intelligence SaaS, confirmed that attackers stole OAuth tokens used to access customers' Salesforce instances; the Icarus extortion group claims responsibility and the incident is part of a broader campaign targeting SaaS-to-Salesforce integrations, risking wide-scale CRM data exposure — revoke tokens, audit connected apps, enable event monitoring, and implement a third-party breach runbook.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
