← Insurity

2026 Insurity — Klue/Salesforce OAuth supply-chain incident; CRM secrets under review

2026 Unknown records affected Share on X

Data compromised

Investigation focused on Salesforce-held customer data and exposed CRM secrets/credentials—initial review found very limited active credentials, all rotated; Insurity cloud and managed infrastructure not impacted per status notices

Technical writeup

Downstream Klue supply-chain victim — June 2026. Insurity status page incident vhhrc014kn85 documented Salesforce notification June 16 of suspicious Klue connected-app activity. Insurity confirmed its cloud, managed infrastructure, and product systems were not impacted; investigation focused on whether customer data or secrets within Salesforce were exposed. A subsequent update stated initial review of exposed CRM secrets identified a very limited set of active credentials, all proactively rotated—organizations not directly contacted were told no connected secrets were impacted. Part of the industry-wide Klue OAuth/Icarus campaign (klue-oauth-supply-chain2026). BreachHistory indexes recordsAffected 0 pending Salesforce data scope attestation.

Root cause

Suspicious activity on Klue connected Salesforce application notified by Salesforce June 16; multi-customer Klue OAuth campaign (Icarus)

References