2026 Jamf — Klue OAuth supply-chain breach; Salesforce instance data accessed
Data compromised
Primarily business data fields within Jamf Salesforce environment per ongoing investigation—no impact to Jamf products or customer service delivery; phishing risk from exposed CRM contacts
Technical writeup
Downstream Klue supply-chain victim — June 2026. Jamf disclosed June 18 that an unauthorized party accessed Jamf's Salesforce instance data through Klue's integration after Klue's environment was compromised. Jamf immediately disabled the Klue Salesforce integration, engaged forensic experts and law enforcement, and reported no evidence of lateral movement or impact to Jamf products/Apple device management services. Customer communication warned of possible phishing impersonating Jamf employees using Salesforce contact data. Investigation ongoing at initial blog publication. Indexed under klue-oauth-supply-chain2026 Icarus OAuth campaign.
Root cause
Unauthorized party accessed Jamf Salesforce data through compromised Klue competitive-intelligence integration (Icarus supply-chain)