logo

Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

ID: c13811d2-b7de-5e07-984c-199a1fad2867

STIX ID: report--c13811d2-b7de-5e07-984c-199a1fad2867

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: [email protected] (The Hacker News)

...
...

Salesforce disabled the Klue Battlecards app after Klue detected unauthorized activity in its integration infrastructure: attackers used a long-unused credential to push code that collected OAuth tokens, then used those tokens to query customer Salesforce orgs and exfiltrate CRM and sales-related data (Huntress confirmed impact). Klue revoked credentials and tokens, removed unauthorized code, disabled affected integrations, and launched an investigation; analysts link the activity to automated OAuth-abuse playbooks that enable bulk data retrieval from trusted third-party integrations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.