← Klue

2026 Klue — OAuth token theft supply-chain attack; Salesforce CRM data exfiltrated from customers

2026 Unknown records affected Share on X

Data compromised

OAuth tokens used to query and exfiltrate downstream CRM/sales data—disclosed downstream victims indexed separately: LastPass, Huntress, Recorded Future, Tanium, Jamf, Sprout Social, Gong, Insurity, Bynder; Icarus leak site June 21 threatened additional Salesforce partners; no unified public victim count

Technical writeup

In mid-June 2026 Huntress, ReliaQuest, and BleepingComputer documented a supply-chain compromise at Klue, a competitive-intelligence platform. Attackers began June 11 with anomalous behavior in Klue integration systems, deploying code that collected OAuth tokens Klue customers use to connect Salesforce, HubSpot, Gong, SharePoint, Zoom, Clari, Slack, and Google Drive. Klue deactivated OAuth credentials June 12, alerted customers June 13, and disabled integrations while investigating; CEO Jason Smith publicly confirmed unauthorized activity June 12 affecting integration infrastructure. The Icarus extortion group emailed victims June 16 demanding contact within 48 hours and listed Klue on its leak site June 21, threatening downstream Salesforce partners if Klue did not respond. BreachHistory indexes nine publicly disclosed downstream victims with separate rows: lastpass-klue-salesforce2026, huntress-klue-salesforce2026, recorded-future-klue-salesforce2026, tanium-klue-salesforce2026, jamf-klue-salesforce2026, sprout-social-klue-salesforce2026, gong-klue-salesforce2026, insurity-klue-salesforce2026, and bynder-klue-salesforce2026. LastPass confirmed June 23, 2026 (BleepingComputer). Salesforce disabled the Klue Battlecards integration. BreachHistory indexes recordsAffected 0 on the Klue parent row pending per-customer regulatory filings.

Root cause

Compromised Klue backend; malicious code update harvested customer OAuth tokens for Salesforce, Gong, HubSpot, and other integrations (Icarus extortion actor)

References