logo

Klue breach lead to Salesforce data theft, Huntress affected

ID: 47acce36-7fb8-5ad2-89ea-373e9155163a

STIX ID: report--47acce36-7fb8-5ad2-89ea-373e9155163a

Feed Name: Help Net Security

Threat Score
70/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Zeljka Zorz

...
...

The report covers a breach at market-intelligence vendor Klue where attackers exploited a dormant API credential to deploy malicious code that harvested OAuth tokens for integrations (Salesforce, HubSpot, Slack, Google Drive, etc.), enabling exfiltration of customer CRM and sales data; Huntress confirmed it was impacted and linked the activity to an extortion group called 'Icarus', while Salesforce disabled the Klue app and Klue revoked credentials and removed the unauthorized code.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.