logo

Klue OAuth Breach Victim List Grows as Icarus Claims Responsibility

ID: cebba92a-689b-5927-85bf-e18fcbe5d1cd

STIX ID: report--cebba92a-689b-5927-85bf-e18fcbe5d1cd

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-06-21

Date Updated: 2026-06-21

Author: John Kevin Hao

...
...

Klue confirmed an incident in which attackers used a compromised legacy credential to steal OAuth tokens for its Battlecards Salesforce integration, allowing access to Salesforce CRM data across multiple customer organizations; the Icarus extortion group claimed responsibility and threatened downstream victims. Klue revoked credentials and tokens, disabled affected integrations, engaged CrowdStrike, and notified law enforcement. Recommended mitigations include auditing and minimizing OAuth application permissions, rotating tokens after third-party incidents, and monitoring cloud API activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.