logo

Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks

ID: 09233bae-11df-5743-ac68-998b443c8425

STIX ID: report--09233bae-11df-5743-ac68-998b443c8425

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Lawrence Abrams

...
...

Klue's Battlecards integration was breached, allowing attackers (identified as the Icarus extortion group) to steal OAuth tokens and use Salesforce REST API queries to exfiltrate CRM data from multiple organizations; security firms ReliaQuest and Huntress confirmed the incident, and victims are being extorted while Salesforce disabled the Klue integration. Organizations are advised to revoke and rotate OAuth tokens, terminate sessions, review Salesforce and related SaaS logs for activity from the listed IPs, and investigate unusual API queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.