← Jamf

2026 Jamf — Klue OAuth supply-chain breach; Salesforce instance data accessed

2026 Unknown records affected Share on X

Data compromised

Primarily business data fields within Jamf Salesforce environment per ongoing investigation—no impact to Jamf products or customer service delivery; phishing risk from exposed CRM contacts

Technical writeup

Downstream Klue supply-chain victim — June 2026. Jamf disclosed June 18 that an unauthorized party accessed Jamf's Salesforce instance data through Klue's integration after Klue's environment was compromised. Jamf immediately disabled the Klue Salesforce integration, engaged forensic experts and law enforcement, and reported no evidence of lateral movement or impact to Jamf products/Apple device management services. Customer communication warned of possible phishing impersonating Jamf employees using Salesforce contact data. Investigation ongoing at initial blog publication. Indexed under klue-oauth-supply-chain2026 Icarus OAuth campaign.

Root cause

Unauthorized party accessed Jamf Salesforce data through compromised Klue competitive-intelligence integration (Icarus supply-chain)

References