logo

Klue Supply Chain Compromise and CRM Data Exfiltration Incident Advisory

ID: a819fd51-007c-5165-a261-8d28ca2e6cf1

STIX ID: report--a819fd51-007c-5165-a261-8d28ca2e6cf1

Feed Name: Kudelski Security

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-07-22

...
...

A supply-chain compromise of the Klue platform led to malicious backend code that harvested customer OAuth tokens; those tokens were then used to authenticate into downstream SaaS services (including Salesforce, HubSpot, Google Drive, Slack and others) to perform automated, bulk CRM and sales data exfiltration. The report provides technical telemetry (abnormal /services/data/v59.0/query/ activity, Python-urllib user agents, non-standard User-Agent values), four IP IOCs, and mitigation guidance such as immediate token revocation, log review, and vendor coordination.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.