AUTO-UPDATED

Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data

Salesforce has disabled the Klue Battlecards integration after the threat group Icarus exploited a legacy credential to steal OAuth tokens and exfiltrate sensitive customer data from connected CRM environments.

Key Points

  • Salesforce disabled the Klue app on June 11, 2026, following unauthorized access to customer data via the integration.
  • The threat actor Icarus used a compromised legacy credential to access Klue’s infrastructure and steal OAuth tokens.
  • Stolen tokens allowed attackers to bypass standard authentication and perform bulk data extraction from Salesforce environments.
  • Impacted companies include Huntress, Jamf, Recorded Future, Tanium, Gong, and Sprout Social.
  • Compromised data primarily includes business contacts, sales quotes, and account information, rather than core product telemetry or passwords.
  • Klue has revoked affected credentials, removed unauthorized code, and is working with impacted customers to mitigate the breach.

Why it Matters

This incident highlights the growing risk of SaaS supply chain attacks where threat actors target trusted third-party vendors to gain broad access to multiple enterprise environments simultaneously. It underscores the critical need for organizations to monitor non-human identities and OAuth integrations as rigorously as they monitor standard employee user accounts.
Internet Published by info@thehackernews.com (The Hacker News)
Read original