Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1513+ Articles
152+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Klue OAuth Breach Linked to 'Icarus' Salesforce Data Theft Attacks
Klue OAuth Breach Linked to 'Icarus' Salesforce Data Theft Attacks
NEWS

Klue OAuth Breach Linked to 'Icarus' Salesforce Data Theft Attacks

Market intelligence platform Klue suffered an OAuth breach that enabled the 'Icarus' threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign.

Dylan H.

News Desk

June 18, 2026
3 min read

Market intelligence platform Klue has disclosed a breach through its OAuth integration that allowed a threat group tracked as "Icarus" to exfiltrate Salesforce CRM data from multiple downstream organizations. The breach has been tied to an active extortion campaign targeting Klue's enterprise customer base.

What Happened

Attackers exploited OAuth tokens associated with Klue's platform integrations to gain unauthorized access to connected Salesforce instances. By abusing legitimate OAuth authorization flows, the Icarus group was able to pivot from Klue's environment into customers' CRM data — including contact records, deal pipelines, and potentially sensitive business intelligence.

The breach is described as part of an ongoing campaign, with affected organizations receiving extortion demands as the group threatens to publish or sell stolen data.

OAuth as an Attack Vector

This incident continues a growing trend of threat actors targeting OAuth integrations between SaaS platforms rather than attempting direct breaches. When a vendor like Klue holds OAuth refresh tokens with broad scopes, a single compromise can fan out across an entire customer base.

Key characteristics of the Icarus technique include:

  • Token harvesting from the integration layer rather than user credentials
  • Lateral movement from one SaaS platform to connected platforms via authorized app chains
  • Low-noise persistence — OAuth tokens are long-lived and rarely audited for suspicious usage patterns

Impact Assessment

While Klue has not disclosed exact victim counts, the attack affected multiple enterprise customers who had Salesforce integrated via Klue's market intelligence workflows. Salesforce data exposed in these incidents typically includes:

  • Sales pipeline and deal stage information
  • Customer contact details and account hierarchies
  • Internal notes, activity logs, and competitive intelligence

The extortion element suggests the Icarus group is prioritizing monetization over espionage — a pattern consistent with financially motivated ransomware-adjacent actors.

Mitigation Steps

Organizations using Klue or similar market intelligence platforms with Salesforce integrations should take the following actions immediately:

  1. Audit connected OAuth applications in Salesforce Setup → Connected Apps
  2. Revoke and re-issue OAuth tokens for any third-party integrations
  3. Review Salesforce login history and API usage logs for anomalous access
  4. Enable Salesforce Shield Event Monitoring if not already active
  5. Contact Klue for incident-specific guidance on affected tenants

Broader Context

The Icarus group joins a growing list of threat actors — including the Coinbase extortion cartel and groups behind the Grafana and GitHub breaches earlier in 2026 — that have pivoted to targeting the interconnected SaaS supply chain rather than attacking infrastructure directly.

OAuth sprawl, where enterprises accumulate dozens of third-party integrations with excessive scopes and no rotation policies, remains one of the highest-risk unmanaged attack surfaces in modern enterprise environments.


Source: BleepingComputer

#Data Breach#OAuth#Salesforce#Threat Actors

Related Articles

Salesforce Data Thefts Continue via Klue App Compromise

Klue's Battlecards competitive intelligence application has become the third integrated app compromised in the ongoing Icarus campaign targeting Salesforce customer data — with victims including Huntress, a prominent cybersecurity vendor.

5 min read

Kodak Admits Data Breach After ShinyHunters Hack Claims

Eastman Kodak has confirmed a cybersecurity incident following claims by the prolific ShinyHunters threat actor, though the company says it believes there is no ongoing threat to its systems or operations.

3 min read

Infinite Campus Data Breach Affects 137,000 School Staff Accounts

The ShinyHunters extortion gang stole personal information from over 137,000 school staff accounts via a Salesforce data theft attack targeting the widely used Infinite Campus K-12 student information system.

3 min read
Back to all News