Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
ID: 09233bae-11df-5743-ac68-998b443c8425
STIX ID: report--09233bae-11df-5743-ac68-998b443c8425
Feed Name: Bleeping Computer
Klue's Battlecards integration was breached, allowing attackers (identified as the Icarus extortion group) to steal OAuth tokens and use Salesforce REST API queries to exfiltrate CRM data from multiple organizations; security firms ReliaQuest and Huntress confirmed the incident, and victims are being extorted while Salesforce disabled the Klue integration. Organizations are advised to revoke and rotate OAuth tokens, terminate sessions, review Salesforce and related SaaS logs for activity from the listed IPs, and investigate unusual API queries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
