logo

Klue OAuth Breach Linked to 'Icarus' Salesforce Data Theft Attacks

ID: a849281d-2b46-50b0-9933-b6cb1e0a5bff

STIX ID: report--a849281d-2b46-50b0-9933-b6cb1e0a5bff

Feed Name: CosmicBytez Labs

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

...
...

**Executive summary:** Klue disclosed that the Icarus group exploited OAuth tokens in Klue's Salesforce integrations to access and exfiltrate customers' CRM data (contacts, deal pipelines, notes) and is using the stolen data in an active extortion campaign; the report highlights OAuth token harvesting, lateral SaaS pivoting, low-noise persistence, and recommends auditing/revoking connected apps and tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.