Salesforce has disabled the Klue Battlecards integration after the threat group Icarus exploited a legacy credential to steal OAuth tokens and exfiltrate sensitive customer data from connected CRM environments.
Key Points
- Salesforce disabled the Klue app on June 11, 2026, following unauthorized access to customer data via the integration.
- The threat actor Icarus used a compromised legacy credential to access Klue’s infrastructure and steal OAuth tokens.
- Stolen tokens allowed attackers to bypass standard authentication and perform bulk data extraction from Salesforce environments.
- Impacted companies include Huntress, Jamf, Recorded Future, Tanium, Gong, and Sprout Social.
- Compromised data primarily includes business contacts, sales quotes, and account information, rather than core product telemetry or passwords.
- Klue has revoked affected credentials, removed unauthorized code, and is working with impacted customers to mitigate the breach.