logo

Klue OAuth breach victim list grows as Icarus hackers claim attack

ID: cce8ab11-226d-5f8d-87be-1f10ac1cd169

STIX ID: report--cce8ab11-226d-5f8d-87be-1f10ac1cd169

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Lawrence Abrams

...
...

Klue disclosed unauthorized activity on June 12 where a compromised legacy integration credential allowed attackers to generate OAuth tokens and access multiple customers' Salesforce environments; the Icarus extortion group has claimed responsibility and several victim companies reported theft of business contacts, sales communications, pricing and other CRM data. Klue revoked tokens, disabled impacted integrations, removed unauthorized code, notified law enforcement, and engaged CrowdStrike while victims were warned about follow-on phishing and extortion risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.