www.infosecurity-magazine.com 6/22/2026, 10:20:42 AM · external

Klue breach leaks OAuth tokens, puts cybersecurity firms on alert

Klue breach leaks OAuth tokens, puts cybersecurity firms on alert
Developing story breach 2 articles tracked
Klue Salesforce integration breach exposes OAuth tokens
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
Icarus

THE article discusses a security breach at Klue, a business intelligence provider, which has affected multiple cybersecurity firms. Unauthorized access was gained through a compromised legacy credential leading to the theft of OAuth tokens that allowed hackers to infiltrate connected Salesforce accounts.

Affected firms, including Huntress, ReliaQuest, Recorded Future, Jamf, and Tanium, confirmed their services were not directly impacted but warned about potential exposures, including customer data and threat of phishing attacks. Klue's response involved revoking compromised credentials, engaging forensic experts, and keeping customers informed. The breach was attributed to a newly identified group, Icarus, which threatened to release stolen data.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline