Klue OAuth breach lets Icarus steal Salesforce customer data
Hackers broke into competitive-intelligence vendor Klue using a leftover credential from a 2022 pilot program and stole OAuth tokens that let Klue's software connect to customers' Salesforce accounts. A group calling itself Icarus used those tokens to pull data out of roughly two dozen companies' Salesforce systems and tried to extort them, and a second group later claimed to have obtained the stolen data and began extorting some victims again. Salesforce disabled the Klue integration on July 5 to cut off further access.
- Started
- Jun 12, 2026
- Latest activity
- Jul 16, 2026
- Attributed to
- IcarusLikely
- Where
- United States
- Sectors
- Technology, Multiple sectors
- Scale
- roughly two dozen companies, including several well-known cybersecurity and technology firms
Current status
A July 27, 2026 CSO Online retrospective analyzed the Klue/Icarus breach as a case study but reported no new attacker activity, new victims, or restoration/closure milestones since the July 16 report of a no-publish deal with Icarus.
Dormant: No new confirmed activity for a while, and nobody has called an official all clear.
Who is behind it
The extortion group named itself Icarus on its leak site and in victim emails, and security firm Huntress independently linked the activity to Icarus through messaging IDs used in the extortion messages; no government agency has attributed the attack.
Impact
Attackers used stolen OAuth tokens to copy customer records out of Salesforce CRM instances belonging to Klue's client companies, then threatened to leak the data unless victims paid. A July 16 retrospective reported that Klue reached an agreement with Icarus not to publish the stolen data, which suggests a payment was made, though Klue itself has not confirmed paying. A second, separate group claimed to have obtained the same stolen data from Icarus and began extorting some of the same victims again.
What to do
If your organization used Klue's Salesforce integration, confirm whether you were notified and rotate any credentials or tokens tied to that connection; there is no action needed for the general public beyond watching for phishing that references stolen CRM data.
Timeline
-
Aug 30, 2026
No new confirmed activity reported, so this incident moved to dormant while it stays open.
Dormant -
Jul 16, 2026
A TechCrunch year-in-review report said Klue reached a deal with the Icarus hackers not to publish the stolen customer data, strongly suggesting Klue paid a ransom, while a separate hacking group that also obtained a portion of the data continued to hold and threaten to leak it.
Containedtech.yahoo.com -
Jul 9, 2026
Insurity said its forensic work and review of affected records were still ongoing.
Containedstatus.insurity.com -
Jul 5, 2026
Salesforce disabled the Klue integration for its platform, cutting off the access path the attackers had used.
Containedfinance.yahoo.com -
Jun 26, 2026
SecurityWeek reported roughly two dozen companies had notified their own customers about the impact.
Dormantsecurityweek.com -
Jun 26, 2026
SecurityWeek reported that roughly two dozen companies had by then notified their own customers about the Klue-linked breach.
securityweek.com -
Jun 25, 2026
Icarus claimed it was deleting the stolen customer data, but a second, separate hacker group claimed to have obtained the same data and began extorting some victims on its own.
thenextweb.com -
Jun 24, 2026
Password manager LastPass confirmed it was also affected by the Klue-linked Salesforce breach.
tech.yahoo.com -
Jun 23, 2026
Klue confirmed the credential used by the attackers dated back to a 2022 pilot program that had never been revoked.
Activetechcrunch.com -
Jun 23, 2026
Klue said the attackers used a credential left over from a 2022 pilot program that had never been revoked to steal the OAuth tokens.
techcrunch.com -
Jun 22, 2026
The Icarus group listed additional named victims on its leak site, including Huntress.
Activeransomware.live -
Jun 22, 2026
Cybersecurity firms Huntress, HackerOne, Jamf, Recorded Future, and Tanium confirmed their Salesforce data was stolen through the Klue integration.
Activeinfosecurity-magazine.com -
Jun 19, 2026
A group calling itself Icarus posted a claim on a leak site saying it had stolen Salesforce data from Klue and its partner companies.
Activeransomware.live -
Jun 19, 2026
The list of confirmed victims grew as more companies disclosed they were affected by the Klue OAuth breach.
Activebleepingcomputer.com -
Jun 18, 2026
Reports emerged that attackers used stolen OAuth tokens from the Klue Battlecards integration to pull Salesforce CRM data, prompting Salesforce to disable the connection.
Activevpncentral.com -
Jun 18, 2026
Klue confirmed an OAuth token breach that let attackers reach customers' Salesforce environments, with the activity linked to a group calling itself Icarus.
Emergingbleepingcomputer.com -
Jun 12, 2026
Klue detected unauthorized activity on its systems using a compromised legacy credential.
Emergingsocradar.io
Sources
- Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks Bleeping Computer Jun 18, 2026
- Scope of Salesforce Attacks Expands as Icarus Leaks Data Dark Reading Jun 22, 2026
- Klue Breach Enables Hackers to Compromise Cybersecurity Firms via OAuth Tokens Infosecurity Magazine Jun 22, 2026
- Klue says hackers stole credential from 2022 that led to customer data breaches TechCrunch Jun 23, 2026
- Klue says the hackers who stole its customer data are deleting it, but now a second group is making threats The Next Web Jun 25, 2026
- More Klue Breach Victims Identified as Hackers Get Hacked SecurityWeek Jun 26, 2026
- Salesforce (CRM) Disables Klue Integration After Data Breach Exposes Customer Data Yahoo Finance Jul 5, 2026
- When the hackers get hacked: The Klue breach and the new reality of third-party cyber risk CSO Online Jul 27, 2026
- Klue breach leaks Salesforce customer data VPNCentral Jun 18, 2026
- Klue ransomware attack leaks Salesforce data SOCRadar Jun 24, 2026 unverified
- Cybersecurity Firms Impacted by Klue Supply Chain Attack SecurityWeek Jun 19, 2026
- Detecting the Klue supply chain attack in Salesforce instances Datadog Security Labs Jun 22, 2026
- Notification of Salesforce / Klue Security Incident Insurity Jul 9, 2026
- Hacked, leaked, and held for ransom: The worst breaches of 2026 so far Yahoo Tech / TechCrunch Jul 16, 2026
Related reports
- Oracle Klue OAuth tokens break into Salesforce accounts Jun 26, 2026
- More Klue customers hacked in Salesforce breach Jun 26, 2026
- Klue breach leaks Salesforce customer data Jun 23, 2026
- Icarus ransomware claims H* Jun 23, 2026
- Detecting the Klue supply chain attack in Salesforce instances Jun 22, 2026
- Klue breach leaks OAuth tokens from cybersecurity firms Jun 22, 2026
- Icarus ransomware claims Huntress Jun 22, 2026
- Icarus ransomware claims HDS (Hdscorp) Jun 22, 2026
- Icarus ransomware claims Gms-net Jun 22, 2026
- Icarus ransomware claims Cqcrm Jun 22, 2026
- Icarus ransomware claims Cbassociations Jun 22, 2026
- Scope of Salesforce Attacks Expands as Icarus Leaks Data Jun 22, 2026