Klue breach lead to Salesforce data theft, Huntress affected
ID: 47acce36-7fb8-5ad2-89ea-373e9155163a
STIX ID: report--47acce36-7fb8-5ad2-89ea-373e9155163a
Feed Name: Help Net Security
The report covers a breach at market-intelligence vendor Klue where attackers exploited a dormant API credential to deploy malicious code that harvested OAuth tokens for integrations (Salesforce, HubSpot, Slack, Google Drive, etc.), enabling exfiltration of customer CRM and sales data; Huntress confirmed it was impacted and linked the activity to an extortion group called 'Icarus', while Salesforce disabled the Klue app and Klue revoked credentials and removed the unauthorized code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
