logo

Klue Integration Abused in Salesforce Data Theft

ID: f4ab20a7-cbb1-539b-b2ce-776cbb803301

STIX ID: report--f4ab20a7-cbb1-539b-b2ce-776cbb803301

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2026-06-17

Date Updated: 2026-06-18

...
...

ReliaQuest observed a compromised Klue integration used to exfiltrate Salesforce CRM data by generating OAuth tokens and running automated REST API queries (Python-urllib user-agent) over sustained windows, including a burst of nearly 1,000 queries in 15 minutes; exfiltration is confirmed though scope, initial access vector, and intent remain under investigation. The activity mirrors prior 2025–2026 Salesforce OAuth-abuse campaigns, includes observable IOCs (four IP addresses), and the report recommends revoking/rotating tokens and credentials, hunting Salesforce API logs for anomalous query patterns, and restricting API access to allowlisted infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.