← Huntress

2026 Huntress — Klue OAuth supply-chain breach; Salesforce & Gong CRM data exfiltrated

2026 Unknown records affected Share on X

Data compromised

Business contacts, price quotes, sales communications, opportunity notes, subscription/pricing details, competitive market reports per Huntress—no threat intel, customer credentials, payment/PCI data, or Huntress product/agent telemetry

Technical writeup

Downstream Klue supply-chain victim — June 2026. Huntress publicly disclosed that the Icarus extortion group's compromise of Klue (see klue-oauth-supply-chain2026) enabled exfiltration from Huntress's Salesforce and Gong environments via stolen Klue integration OAuth tokens. Huntress confirmed copied data included business contacts (names, work emails, titles, phones, business addresses), pricing/quotes, sales messaging, and opportunity notes—not threat intelligence, customer/partner credentials, payment data, or Huntress product telemetry. Icarus emailed Huntress staff June 16 with 48-hour extortion demands; Huntress tied Session Messenger IDs to the Icarus leak site. Primary incident at Klue began June 11; Huntress published investigation details June 17–19. BreachHistory indexes recordsAffected 0 pending CRM row counts.

Root cause

Icarus actor compromised Klue backend June 11; stolen OAuth tokens used to query Huntress Salesforce and Gong integrations directly

References