Dormant High impact Supply chain Checked 1w ago

Klue OAuth breach lets Icarus steal Salesforce customer data

Hackers broke into competitive-intelligence vendor Klue using a leftover credential from a 2022 pilot program and stole OAuth tokens that let Klue's software connect to customers' Salesforce accounts. A group calling itself Icarus used those tokens to pull data out of roughly two dozen companies' Salesforce systems and tried to extort them, and a second group later claimed to have obtained the stolen data and began extorting some victims again. Salesforce disabled the Klue integration on July 5 to cut off further access.

Started
Jun 12, 2026
Latest activity
Jul 16, 2026
Attributed to
IcarusLikely
Where
United States
Sectors
Technology, Multiple sectors
Scale
roughly two dozen companies, including several well-known cybersecurity and technology firms

Current status

A July 27, 2026 CSO Online retrospective analyzed the Klue/Icarus breach as a case study but reported no new attacker activity, new victims, or restoration/closure milestones since the July 16 report of a no-publish deal with Icarus.

Dormant: No new confirmed activity for a while, and nobody has called an official all clear.

Who is behind it

The extortion group named itself Icarus on its leak site and in victim emails, and security firm Huntress independently linked the activity to Icarus through messaging IDs used in the extortion messages; no government agency has attributed the attack.

Impact

Attackers used stolen OAuth tokens to copy customer records out of Salesforce CRM instances belonging to Klue's client companies, then threatened to leak the data unless victims paid. A July 16 retrospective reported that Klue reached an agreement with Icarus not to publish the stolen data, which suggests a payment was made, though Klue itself has not confirmed paying. A second, separate group claimed to have obtained the same stolen data from Icarus and began extorting some of the same victims again.

What to do

If your organization used Klue's Salesforce integration, confirm whether you were notified and rotate any credentials or tokens tied to that connection; there is no action needed for the general public beyond watching for phishing that references stolen CRM data.

Timeline

  1. Aug 30, 2026

    No new confirmed activity reported, so this incident moved to dormant while it stays open.

    Dormant
  2. Jul 16, 2026

    A TechCrunch year-in-review report said Klue reached a deal with the Icarus hackers not to publish the stolen customer data, strongly suggesting Klue paid a ransom, while a separate hacking group that also obtained a portion of the data continued to hold and threaten to leak it.

    Containedtech.yahoo.com
  3. Jul 9, 2026

    Insurity said its forensic work and review of affected records were still ongoing.

    Containedstatus.insurity.com
  4. Jul 5, 2026

    Salesforce disabled the Klue integration for its platform, cutting off the access path the attackers had used.

    Containedfinance.yahoo.com
  5. Jun 26, 2026

    SecurityWeek reported roughly two dozen companies had notified their own customers about the impact.

    Dormantsecurityweek.com
  6. Jun 26, 2026

    SecurityWeek reported that roughly two dozen companies had by then notified their own customers about the Klue-linked breach.

    securityweek.com
  7. Jun 25, 2026

    Icarus claimed it was deleting the stolen customer data, but a second, separate hacker group claimed to have obtained the same data and began extorting some victims on its own.

    thenextweb.com
  8. Jun 24, 2026

    Password manager LastPass confirmed it was also affected by the Klue-linked Salesforce breach.

    tech.yahoo.com
  9. Jun 23, 2026

    Klue confirmed the credential used by the attackers dated back to a 2022 pilot program that had never been revoked.

    Activetechcrunch.com
  10. Jun 23, 2026

    Klue said the attackers used a credential left over from a 2022 pilot program that had never been revoked to steal the OAuth tokens.

    techcrunch.com
  11. Jun 22, 2026

    The Icarus group listed additional named victims on its leak site, including Huntress.

    Activeransomware.live
  12. Jun 22, 2026

    Cybersecurity firms Huntress, HackerOne, Jamf, Recorded Future, and Tanium confirmed their Salesforce data was stolen through the Klue integration.

    Activeinfosecurity-magazine.com
  13. Jun 19, 2026

    A group calling itself Icarus posted a claim on a leak site saying it had stolen Salesforce data from Klue and its partner companies.

    Activeransomware.live
  14. Jun 19, 2026

    The list of confirmed victims grew as more companies disclosed they were affected by the Klue OAuth breach.

    Activebleepingcomputer.com
  15. Jun 18, 2026

    Reports emerged that attackers used stolen OAuth tokens from the Klue Battlecards integration to pull Salesforce CRM data, prompting Salesforce to disable the connection.

    Activevpncentral.com
  16. Jun 18, 2026

    Klue confirmed an OAuth token breach that let attackers reach customers' Salesforce environments, with the activity linked to a group calling itself Icarus.

    Emergingbleepingcomputer.com
  17. Jun 12, 2026

    Klue detected unauthorized activity on its systems using a compromised legacy credential.

    Emergingsocradar.io

Sources

Related reports