www.securityweek.com 6/26/2026, 3:31:38 PM · external

Klue supply chain hack leaks Salesforce data at two dozen firms

Klue supply chain hack leaks Salesforce data at two dozen firms
Developing story campaign 4 articles tracked
Klue supply chain breach exposes Salesforce OAuth tokens
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
Icarus

A supply chain attack targeting the market intelligence platform Klue compromised the Salesforce instances of approximately two dozen customers between June 11 and 12. Hackers utilized old credentials to gain access, exfiltrating data including business contacts. The affected organizations include notable names such as BeyondTrust, LastPass, and AlertMedia. Klue's integration with Salesforce was disabled on June 17 and has not been reinstated.

The threat actor, known as Icarus, threatened to leak stolen data unless a ransom was paid. Reports indicate that negotiations may have occurred, resulting in the deletion of some stolen data by Icarus. The attack potentially impacts 195 customers, with the total effects still being assessed.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline