2026 Sprout Social — Klue OAuth supply-chain breach; Salesforce CRM contacts exfiltrated
Data compromised
Business contact details (names, professional emails, phones, titles, mailing addresses), organizational/account info, commercial CRM records—no Sprout Social product data, social profile credentials, published content, auth passwords, or platform API keys
Technical writeup
Downstream Klue supply-chain victim — June 2026. Sprout Social confirmed a Klue vendor incident allowed unauthorized access to its Salesforce CRM during June 11–12, 2026. Exposed categories may include business contacts, company/account metadata, and commercial CRM records. Sprout stated no impact to the Sprout Social application, connected social profiles, scheduled content, passwords, or API keys; activity was limited to Salesforce CRM separate from Salesforce Service Cloud product integration. Sprout disabled the Salesforce connected app, deactivated Klue service accounts, removed other Klue integrations, and warned of follow-on phishing/extortion tied to exposed contacts. Part of klue-oauth-supply-chain2026.
Root cause
Threat actor obtained Klue integration credentials and accessed Sprout Social Salesforce CRM June 11–12 (Icarus supply-chain)