[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRC_hMLQVIxi0jg--1G3iBXPzLvN1cYZFDWe6ocoxdPQ":3},{"article":4,"iocs":56},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":33,"category":34,"article_tags":38},"7ae3931e-15ff-4940-b6f7-486d8795acc9","Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks","klue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks-4e6c61","Market intelligence platform Klue suffered a OAuth breach that enabled the \"Icarus\" threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign. [...]","The market intelligence platform Klue experienced an OAuth breach, allowing the 'Icarus' threat actors to access customer Salesforce CRM data. Attackers used stolen OAuth tokens to query Salesforce's REST API, exfiltrating sensitive information over extended periods. Salesforce has since disabled the Klue Battlecards integration to mitigate further damage.","Klue OAuth breach enables 'Icarus' threat actors to steal and extort Salesforce CRM data.","Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks By Lawrence Abrams June 18, 2026 10:19 AM 0 Market intelligence platform Klue suffered a OAuth breach that enabled the \"Icarus\" threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign. Sources told BleepingComputer of the attack yesterday, telling us that numerous organizations had their Salesforce data stolen and were now being extorted by the relatively new extortion group. Cybersecurity firms ReliaQuest and Huntress have both published reports confirming the security incident, with Huntress stating that their Salesforce data was stolen in the attack. Salesforce has since disabled the Klue Battlecards integration on its platform while the breach is investigated. \"To protect our customers, Salesforce has disabled the connection between the Klue Battlecards app, installed by individual customers, and Salesforce as part of our response to a recent security incident,\" Salesforce warned yesterday. \"As a result, organizations will not be able to connect to Salesforce via this app until further notice.\" If you have any information regarding this incident or other undisclosed attacks, you can contact us confidentially via Signal at 646-961-3731 or at tips@bleepingcomputer.com. Stolen OAuth credentials used to steal Salesforce data ReliaQuest stated that attackers gained access to Klue Battlecards integration service accounts and used OAuth tokens associated with customer Salesforce instances to carry out data theft. The researchers observed the threat actors generating OAuth tokens and then using automated Python scripts to query Salesforce's REST API for nearly 24 hours. The activity began with reconnaissance of an organization's Salesforce instances through the '\u002Fservices\u002Fdata\u002Fv59.0\u002Fsobjects' endpoint before exfiltrating data using the '\u002Fservices\u002Fdata\u002Fv59.0\u002Fquery'. ReliaQuest said that for one of the organizations, the attackers slowly mapped out their Salesforce objects to identify valuable objects and then rapidly stole data once they knew what they wanted. \"The attacker then hit the same endpoint, sending almost a thousand queries in a 15-minute window in at least one environment,\" explained ReliaQuest. \"Where the first stage was a slow, steady pull designed to blend in, this burst traded stealth for speed, suggesting either time pressure or a shift to targeted records. In another case, the exfiltration was observed over 6 hours.\" The researchers said the activity closely resembled previous Salesforce third-party integration data theft attacks by the ShinyHunters extortion group, but were unable to attribute the attacks to the threat actor. However, BleepingComputer learned yesterday that ShinyHunters was not behind this attack, but rather a relatively new threat actor known as \"Icarus\" who had already begun emailing extortion demands to Klue customers impacted by the breach. A ransom note shared with BleepingComputer showed that the emails were sent using the alias \"mr bean\" and included a Session Messenger ID to contact them. Icarus extortion emailSource: BleepingComputer The threat actors' data leak site also contains a message hinting at the extortion campaign in a simple post titled \"Get Ready,\" stating, \"big corps getting listed. be ready.\" Message on the Icarus data leak siteSource: BleepingComputer Icarus is believed to have launched in April 2026, and initially listed two victims on its leak site, with BleepingComputer learning that at least one of these victims is connected to the Klue campaign. That company has now been removed from the data leak site, which may indicate that negotiations are underway. Today, Huntress disclosed that it was among the organizations impacted by the Klue breach, confirming that they had received a similar extortion email as seen by BleepingComputer. However, the Session ID used in later emails was different and was instead the one listed on the Icarus data leak site, providing additional evident that they were behind the attack. \"In the initial email, the adversary suggests, 'we advice you to write to us on Session' (sic),\" reported Huntress. \"The Session Messenger ID that they provided matched the same values included on the dark web leak site of a new extortion group dubbed 'Icarus.'\" According to Huntress, Klue told customers that attackers first compromised the company's backend systems and then pushed a malicious code update that stole OAuth tokens customers use to integrate the Battlecards product with third-party platforms. The attackers reportedly used a dormant but still active credential created by Klue for a prototype integration. After gaining access to Klue's environment, they stole customer OAuth tokens and used them to query connected Salesforce environments directly. Klue later disabled integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack while responding to the incident. Huntress said the stolen data includes CRM-related information, including business contacts, sales communications, price quotes, competitive intelligence reports, and account data. The cybersecurity company said there was no evidence that threat intelligence, customer telemetry, passwords, payment card information, or engineering systems were compromised. Both ReliaQuest and Huntress shared IP addresses linked to the attacks, which are listed below: 138.226.246.94 212.86.125.24 213.111.148.90 94.154.32.160 Organizations using Klue integrations are advised to review Salesforce and related SaaS logs for activity originating from these addresses, revoke and rotate OAuth tokens, terminate active sessions, and review Salesforce logs for unusual API activity. Test every layer before attackers do Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection. Get the whitepaper Related Articles: 7-Eleven confirms data breach claimed by the ShinyHunters gangInfinite Campus data breach affects 137,000 school staff accountsOracle PeopleSoft servers hacked in ShinyHunters data theft attacksSilent Ransom Group targets law firms with fake IT support callsCharter Communications data breach affects 4.9 million accounts","https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fklue-oauth-breach-linked-to-icarus-salesforce-data-theft-attacks\u002F","https:\u002F\u002Fwww.bleepstatic.com\u002Fcontent\u002Fhl-images\u002F2022\u002F09\u002F03\u002Fdata-theft.jpeg","2026-06-18T14:19:50+00:00","2026-06-18T16:00:18.853025+00:00",8,[18,21,23,26,29,31],{"name":19,"type":20},"Klue Battlecards","product",{"name":22,"type":20},"Salesforce CRM",{"name":24,"type":25},"Icarus","threat_actor",{"name":27,"type":28},"Klue","vendor",{"name":30,"type":28},"Salesforce",{"name":32,"type":25},"ShinyHunters","2e06f76c-d5b9-4f54-9eef-4d3447b10730",{"id":33,"icon":35,"name":36,"slug":37},null,"Breaches","breaches",[39,44,49,51],{"category":40},{"id":41,"icon":35,"name":42,"slug":43},"26b0b636-0e31-4db1-bffb-61bdf9f20a58","Supply Chain","supply-chain",{"category":45},{"id":46,"icon":35,"name":47,"slug":48},"2c8f44d4-b56e-47cf-9677-04f22c9ee78d","Identity & Access","identity-access",{"category":50},{"id":33,"icon":35,"name":36,"slug":37},{"category":52},{"id":53,"icon":35,"name":54,"slug":55},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[57,60,64,67],{"type":58,"value":24,"context":59},"malware","Threat actor group responsible for the attack.",{"type":61,"value":62,"context":63},"mitre_attack","T1539","OAuth Tokens",{"type":61,"value":65,"context":66},"T1041","Exfiltration Over C2 Channel",{"type":61,"value":68,"context":69},"T1071.001","Web Protocols (Application Layer Protocol: HTTP\u002FHTTPS)"]