Klue OAuth breach victim list grows as Icarus hackers claim attack
ID: cce8ab11-226d-5f8d-87be-1f10ac1cd169
STIX ID: report--cce8ab11-226d-5f8d-87be-1f10ac1cd169
Feed Name: Bleeping Computer
Klue disclosed unauthorized activity on June 12 where a compromised legacy integration credential allowed attackers to generate OAuth tokens and access multiple customers' Salesforce environments; the Icarus extortion group has claimed responsibility and several victim companies reported theft of business contacts, sales communications, pricing and other CRM data. Klue revoked tokens, disabled impacted integrations, removed unauthorized code, notified law enforcement, and engaged CrowdStrike while victims were warned about follow-on phishing and extortion risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
