Klue Integration Abused in Salesforce Data Theft
ID: f4ab20a7-cbb1-539b-b2ce-776cbb803301
STIX ID: report--f4ab20a7-cbb1-539b-b2ce-776cbb803301
Feed Name: ReliaQuest Blog
ReliaQuest observed a compromised Klue integration used to exfiltrate Salesforce CRM data by generating OAuth tokens and running automated REST API queries (Python-urllib user-agent) over sustained windows, including a burst of nearly 1,000 queries in 15 minutes; exfiltration is confirmed though scope, initial access vector, and intent remain under investigation. The activity mirrors prior 2025–2026 Salesforce OAuth-abuse campaigns, includes observable IOCs (four IP addresses), and the report recommends revoking/rotating tokens and credentials, hunting Salesforce API logs for anomalous query patterns, and restricting API access to allowlisted infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
