2026 Insurity — Klue/Salesforce OAuth supply-chain incident; CRM secrets under review
Data compromised
Investigation focused on Salesforce-held customer data and exposed CRM secrets/credentials—initial review found very limited active credentials, all rotated; Insurity cloud and managed infrastructure not impacted per status notices
Technical writeup
Downstream Klue supply-chain victim — June 2026. Insurity status page incident vhhrc014kn85 documented Salesforce notification June 16 of suspicious Klue connected-app activity. Insurity confirmed its cloud, managed infrastructure, and product systems were not impacted; investigation focused on whether customer data or secrets within Salesforce were exposed. A subsequent update stated initial review of exposed CRM secrets identified a very limited set of active credentials, all proactively rotated—organizations not directly contacted were told no connected secrets were impacted. Part of the industry-wide Klue OAuth/Icarus campaign (klue-oauth-supply-chain2026). BreachHistory indexes recordsAffected 0 pending Salesforce data scope attestation.
Root cause
Suspicious activity on Klue connected Salesforce application notified by Salesforce June 16; multi-customer Klue OAuth campaign (Icarus)