← OneTrust

2026 OneTrust — Klue OAuth supply-chain breach; Salesforce business contact data exfiltrated

2026 Unknown records affected Share on X

Data compromised

Sales account data and business contact information from OneTrust's Salesforce CRM: names, email addresses, job titles, phone numbers, and business addresses of customer and prospect contacts

Technical writeup

OneTrust confirmed on June 17, 2026 that it identified unauthorized activity in its Salesforce environment associated with the broader Klue supply-chain incident. The attack originated June 11–12, 2026 when threat actor Icarus used compromised legacy credentials to gain access to Klue's production environment and stole OAuth tokens connecting Klue to customer Salesforce instances. OneTrust's Salesforce CRM data—limited to business contact information and sales account data—was accessed and exfiltrated. OneTrust's internal systems and customer data within its own platform were not affected. Icarus subsequently listed OneTrust among its threatened disclosures on its Tor leak site. CrowdStrike assisted Klue's investigation; Salesforce disabled the Klue integration following the incident.

Root cause

Klue market-intelligence platform breach (June 11–12, 2026) via compromised legacy credentials; OAuth tokens used to access OneTrust's Salesforce CRM

References