Klue acompetitive intelligence company, has been at the center of a serious cybersecurity incident that led to the theft of OAuth tokens and unauthorized access to customer data through Salesforce. Klue announced that it detected unauthorized activity on June 12, 2026, which impacted part of its integration infrastructure, and Salesforce immediately disabled the Klue Battlecards from its platform. The incident highlights once again the risk of third-party integrations in enterprise SaaS.
See also: One-click attack on GitHub Dev allows theft of GitHub OAuth tokens

According to Klue CEO Jason Smith , the attackers initially gained access through an old, forgotten but still active credential that had been created to test a third-party integration that was eventually abandoned. Using this access, the attackers were able to extract OAuth tokens that Klue customers used to connect the app to their own systems, including Salesforce . They then used the stolen tokens to gain direct access to the customers’ CRM tools and extract data.
Salesforce clarified that the disabling of the Klue Battlecards app is not related to a vulnerability in the platform itself, but is a precautionary measure to protect its customers. “ The unusual activity we identified may have led to unauthorized access to a subset of customer data through the app’s connection to Salesforce ,” the company said. Organizations will not be able to connect to Salesforce through the Klue app until further notice.
Klue and the Icarus team: Technical details of the attack
The attack is being carried out by an extortion calling itself Icarus , which appears to have been active since April 28, 2026.The group has claimed a total of two victims to date, with the Klue being the most prominent. Icarus is reminiscent of previous attacks by ShinyHunters and UNC6395, which also targeted third-party integrations to gain access to larger corporate environments.
See also: ShinyHunters claim to be stealing data from Salesforce Aura

Cybersecurity firm Huntress has publicly confirmed that its Salesforce data was affected by the incident. According to Huntress , the data copied from its Salesforce account includes business contacts, quotes, and other sales-related data and messages. The company stressed that no threat data, passwords, payment information, or engineering data related to the Huntress agent were affected . Starting on June 16, 2026 , some Huntress employees received extortion emails with the subject line “top secret email” and a 48-hour deadline to respond.
ReliaQuest researchers Thassanai McCabe and Alexa Feminella technically analyzed the attack and found that the attackers used automated Python scripts — identifiable by Python-urllib user-agent strings — to enumerate the organization’s object catalog via the GET /services/data/v59.0/sobjects endpoint and then execute repeated REST API queries to extract data. ReliaQuest also noted that the attack resembles similar OAuth abuses that targeted Salesforce environments via the Salesloft Drift and Gainsight integrations last year.
Klue said it disabled integrations with at least nine connected platforms as part of its response, including Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive , and Slack. In addition, the company revoked affected credentials and tokens, removed unauthorized code, and disabled remote access, while launching a full investigation.
See also: Hacker claims to have leaked NordVPN's Salesforce data

This incident is a prime example of the growing trend of attacks through the SaaS supply chain : instead of directly attacking large platforms like Salesforce , attackers are targeting less protected third-party providers that have authorized access to them. Once they obtain valid OAuth tokens , their access appears perfectly legitimate to the target platform. Organizations are urged to revoke and renew OAuth tokens for Klue -related integrations , review logs for suspicious API activity — particularly from IP addresses 138.226.246.94 , 212.86.125.24 , 213.111.148.90 , and 94.154.32.160 — and implement the principle of least privilege for third-party applications.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
