Skip to main content
See every side of every news story
Published loading...Updated

Security Shops Among the 'Hundreds' of Klue Hack Victims

Attackers used stolen OAuth tokens to access Salesforce data at hundreds of Klue customers, and several security vendors said their CRM records were exposed.

  • On Friday, Klue CEO Jason Smith disclosed that attackers used a compromised legacy credential to access customer Salesforce environments, enabling the Icarus extortion group to steal data from hundreds of customers.
  • Klue spotted the unauthorized activity a day after the breach occurred on June 11, prompting Mandiant CTO Charles Carmakal to urge organizations to immediately audit their systems for evidence of compromise.
  • Huntress, among the "hundreds of Klue customers" affected, received extortion demands via a "top secret email" from Icarus, while vendors including Recorded Future and Tanium revealed attackers accessed their CRM data.
  • In response, Klue disconnected all integrations with Salesforce, HubSpot, and Google Drive while engaging CrowdStrike to assist with the investigation and security response.
  • While the attack "resembles the 2025 and 2026 third-party OAuth abuse campaigns against Salesforce," researchers have not linked Icarus to ShinyHunters, though the group has been active since April 28.
Insights by Ground AI
Podcasts & Opinions

15 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

IT Brief Australia broke the news on Monday, June 22, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal