www.securityweek.com 6/19/2026, 9:30:39 AM · external

Klue supply chain breach leaks OAuth tokens via Salesforce API

Klue supply chain breach leaks OAuth tokens via Salesforce API
Developing story campaign 4 articles tracked
Klue supply chain breach exposes Salesforce OAuth tokens
CyberSIXT Evidence Panel
Threat Actor
Icarus

A recent supply chain attack affected the market intelligence platform Klue, starting on June 11. Cybersecurity firms Huntress and Recorded Future disclosed unauthorized access to Klue's backend servers, leading to the exfiltration of OAuth tokens and customer data using Salesforce's REST API. Klue suspended integrations with major platforms, including Salesforce and HubSpot, on June 12. On June 17, Salesforce confirmed unusual activity linked to the Klue Battlecards app.

Although Huntress and Recorded Future suffered data breaches involving client contact information, neither faced direct system access breaches. The attack is suspected to be linked to a new threat actor, 'Icarus,' although similar incidents have been previously attributed to 'ShinyHunters' and 'UNC6395.' Klue has not publicly addressed the incident.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline