Klue OAuth breach victim list grows as Icarus hackers claim attack
Klue confirms OAuth token breach exposing customer Salesforce data. The Icarus extortion group claims responsibility as the victim list grows to include Recorded Future, Tanium, Jamf, and others.

Klue Confirms OAuth Token Breach as Icarus Extortion Group Claims Responsibility
Market intelligence platform Klue has publicly confirmed a significant security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments. The disclosure comes as the newly emerged "Icarus" extortion group publicly claims responsibility for the attack, with the list of affected organizations continuing to grow.
How the Breach Unfolded
In a statement published this week, Klue CEO Jason Smith revealed that the company discovered unauthorized activity on June 12 affecting a portion of Klue's integration infrastructure. The investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service.
"The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments," Smith wrote.
Klue says it immediately revoked affected credentials and tokens, removed unauthorized code, disabled impacted integrations, launched an investigation, and notified law enforcement. The company also engaged CrowdStrike to assist with the response efforts. Importantly, Klue stated there is currently no evidence that customer content stored directly within the Klue platform itself was impacted, with the incident limited to third-party integrations.
Security Firms Detail the Attack
Cybersecurity firms ReliaQuest and Huntress have independently analyzed the breach and found that attackers used stolen OAuth credentials associated with Klue integrations to access customer Salesforce environments for large-scale data theft. ReliaQuest observed attackers generating OAuth tokens and using Python scripts to query Salesforce's API over extended periods as data was systematically exfiltrated.
Huntress later disclosed that its own Salesforce environment was affected by the Klue breach, confirming that stolen data included business contacts, sales communications, pricing information, and other sensitive records. Huntress also independently connected the operation to Icarus through Session Messenger IDs used in extortion emails and the group's data leak site.
Icarus Extortion Group Steps Forward
While BleepingComputer and security researchers had previously linked the incident to the Icarus extortion operation, the threat actors have now publicly claimed responsibility on their data leak site.
"As you've probably already heard, Klue.com has been impacted by us recently. A number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated," the Icarus group posted. The threat actors proceeded to pressure Klue and affected organizations to contact them through the Session messaging platform to prevent the leaking of stolen data.
Growing List of Affected Organizations
Since the initial disclosure, the list of affected organizations has continued to expand. Victims that have disclosed being impacted by the breach include:
- Recorded Future — The threat intelligence firm confirmed its Salesforce data was accessed.
- Tanium — The endpoint management company issued a security update regarding data exfiltration from Salesforce.
- Jamf — The Apple device management specialist disclosed its Salesforce environment was compromised.
- Sprout Social — The social media management platform confirmed its Salesforce data was affected.
- Gong — The revenue intelligence platform reported theft of Salesforce data.
- Insurity — The insurance software provider also confirmed its systems were impacted.
Almost all affected organizations have emphasized that the incident led specifically to the theft of data from their Salesforce instances and did not affect their own platforms, infrastructure, payment information, or internal systems.
Phishing and Social Engineering Risks
Multiple affected organizations have warned that the stolen business contact information could be weaponized in follow-on phishing, social engineering, and extortion campaigns. Customers and partners of affected companies are being urged to remain vigilant against suspicious communications that may leverage the stolen data to appear credible.
The incident highlights the cascading risks associated with third-party integrations and OAuth-based authorization. When a platform like Klue connects to customer environments via OAuth tokens, a compromise of the integration layer can create a downstream ripple effect, exposing data across multiple organizations simultaneously.
Industry Implications
The Klue breach serves as a stark reminder of the importance of OAuth token hygiene, credential lifecycle management, and rigorous third-party risk assessment. Security teams are advised to audit their connected application integrations, enforce the principle of least privilege for OAuth scopes, and implement monitoring for anomalous API access patterns that may signal token abuse.
As the investigation continues and the Icarus group's activities draw increased scrutiny from law enforcement and the security community, the incident stands as one of the most consequential supply-chain style attacks of 2026, demonstrating how a single compromised integration can cascade into widespread data exposure across the enterprise ecosystem.


