P
Back to articles
News3 min read

Klue OAuth breach victim list grows as Icarus hackers claim attack

Klue confirms OAuth token breach exposing customer Salesforce data. The Icarus extortion group claims responsibility as the victim list grows to include Recorded Future, Tanium, Jamf, and others.

Source: BleepingComputer
Klue OAuth breach victim list grows as Icarus hackers claim attack

Klue Confirms OAuth Token Breach as Icarus Extortion Group Claims Responsibility

Market intelligence platform Klue has publicly confirmed a significant security incident that allowed threat actors to steal OAuth tokens used to connect to customers' Salesforce environments. The disclosure comes as the newly emerged "Icarus" extortion group publicly claims responsibility for the attack, with the list of affected organizations continuing to grow.

How the Breach Unfolded

In a statement published this week, Klue CEO Jason Smith revealed that the company discovered unauthorized activity on June 12 affecting a portion of Klue's integration infrastructure. The investigation determined that an attacker gained access through a compromised legacy credential associated with an integration service.

"The attacker used that access to obtain OAuth tokens used to connect Klue with certain third-party platforms, including Salesforce, and subsequently accessed data within a number of connected customer environments," Smith wrote.

Klue says it immediately revoked affected credentials and tokens, removed unauthorized code, disabled impacted integrations, launched an investigation, and notified law enforcement. The company also engaged CrowdStrike to assist with the response efforts. Importantly, Klue stated there is currently no evidence that customer content stored directly within the Klue platform itself was impacted, with the incident limited to third-party integrations.

Security Firms Detail the Attack

Cybersecurity firms ReliaQuest and Huntress have independently analyzed the breach and found that attackers used stolen OAuth credentials associated with Klue integrations to access customer Salesforce environments for large-scale data theft. ReliaQuest observed attackers generating OAuth tokens and using Python scripts to query Salesforce's API over extended periods as data was systematically exfiltrated.

Huntress later disclosed that its own Salesforce environment was affected by the Klue breach, confirming that stolen data included business contacts, sales communications, pricing information, and other sensitive records. Huntress also independently connected the operation to Icarus through Session Messenger IDs used in extortion emails and the group's data leak site.

Icarus Extortion Group Steps Forward

While BleepingComputer and security researchers had previously linked the incident to the Icarus extortion operation, the threat actors have now publicly claimed responsibility on their data leak site.

"As you've probably already heard, Klue.com has been impacted by us recently. A number of other companies' Salesforce instances, which were partners to Klue, were exfiltrated," the Icarus group posted. The threat actors proceeded to pressure Klue and affected organizations to contact them through the Session messaging platform to prevent the leaking of stolen data.

Growing List of Affected Organizations

Since the initial disclosure, the list of affected organizations has continued to expand. Victims that have disclosed being impacted by the breach include:

  • Recorded Future — The threat intelligence firm confirmed its Salesforce data was accessed.
  • Tanium — The endpoint management company issued a security update regarding data exfiltration from Salesforce.
  • Jamf — The Apple device management specialist disclosed its Salesforce environment was compromised.
  • Sprout Social — The social media management platform confirmed its Salesforce data was affected.
  • Gong — The revenue intelligence platform reported theft of Salesforce data.
  • Insurity — The insurance software provider also confirmed its systems were impacted.

Almost all affected organizations have emphasized that the incident led specifically to the theft of data from their Salesforce instances and did not affect their own platforms, infrastructure, payment information, or internal systems.

Phishing and Social Engineering Risks

Multiple affected organizations have warned that the stolen business contact information could be weaponized in follow-on phishing, social engineering, and extortion campaigns. Customers and partners of affected companies are being urged to remain vigilant against suspicious communications that may leverage the stolen data to appear credible.

The incident highlights the cascading risks associated with third-party integrations and OAuth-based authorization. When a platform like Klue connects to customer environments via OAuth tokens, a compromise of the integration layer can create a downstream ripple effect, exposing data across multiple organizations simultaneously.

Industry Implications

The Klue breach serves as a stark reminder of the importance of OAuth token hygiene, credential lifecycle management, and rigorous third-party risk assessment. Security teams are advised to audit their connected application integrations, enforce the principle of least privilege for OAuth scopes, and implement monitoring for anomalous API access patterns that may signal token abuse.

As the investigation continues and the Icarus group's activities draw increased scrutiny from law enforcement and the security community, the incident stands as one of the most consequential supply-chain style attacks of 2026, demonstrating how a single compromised integration can cascade into widespread data exposure across the enterprise ecosystem.

Related Articles

Only 10% of SOCs Say They're Getting Excellent Value From AI. Here's What the Second Wave Has to Deliver
News5 min

Only 10% of SOCs Say They're Getting Excellent Value From AI. Here's What the Second Wave Has to Deliver

Only about 10% of SOCs report receiving excellent value from their AI deployments, according to the SOC-CMM 2026 Maturity Report. The report surveyed roughly 200 SOCs and found that 71% saw only some value or none at all — a structural gap driven by off-the-shelf AI deployed without customization. The solution is an architectural shift from point AI tools to agentic SOC platforms that operate across the full security lifecycle.

Security & Privacy
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
News5 min

Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks

Dutch authorities arrested two men and seized over 800 servers used to provide Internet infrastructure for Russian cyberattacks, influence operations, and disinformation campaigns targeting EU member states, in one of the largest takedowns of pro-Russian cyberattack hosting infrastructure in Europe.

Security & Privacy
Botnet of more than 17 million devices dismantled by Dutch authorities
Featured
News4 min

Botnet of more than 17 million devices dismantled by Dutch authorities

Dutch FIOD authorities dismantled a botnet spanning over 17 million infected devices, arresting two men and seizing 800+ servers. The infrastructure supported Russian-linked cybercriminal operations including DDoS attacks, credential stuffing, and cryptocurrency mining. The suspects were charged with violating EU sanctions law.

Security & Privacy
Hackers used Meta's AI support bot to seize Instagram accounts
News4 min

Hackers used Meta's AI support bot to seize Instagram accounts

Attackers hijacked Instagram accounts — including the Obama White House and US Space Force — by manipulating Meta's AI customer support chatbot into changing account recovery emails. The exploit did not affect accounts with MFA enabled. Meta pushed an emergency patch restricting the AI bot's ability to change emails. Security researchers warn this represents a new class of AI-driven social engineering attacks.

Security & Privacy