Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
ID: c13811d2-b7de-5e07-984c-199a1fad2867
STIX ID: report--c13811d2-b7de-5e07-984c-199a1fad2867
Feed Name: The Hacker News
Salesforce disabled the Klue Battlecards app after Klue detected unauthorized activity in its integration infrastructure: attackers used a long-unused credential to push code that collected OAuth tokens, then used those tokens to query customer Salesforce orgs and exfiltrate CRM and sales-related data (Huntress confirmed impact). Klue revoked credentials and tokens, removed unauthorized code, disabled affected integrations, and launched an investigation; analysts link the activity to automated OAuth-abuse playbooks that enable bulk data retrieval from trusted third-party integrations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
