All incidents

Klue supply chain breach exposes Salesforce data of multiple firms

incidentclosedJun 18, 2026 — Jun 24, 2026
Klue supply chain breach exposes customer CRM and Salesforce data

LASTPASS confirmed that a supply chain compromise of the market intelligence provider Klue led to the theft of OAuth tokens and the subsequent exfiltration of customer Salesforce data, a breach that also affected firms such as Gong and 8x8 according to its advisory. The exposed information included names, email addresses and phone numbers taken from connected CRM instances, while LastPass stated that its internal systems remained secure. The intrusion was first observed on 18 June 2026 and continued until at least 24 June 2026, with investigators tracing the initial foothold to a legacy credential within Klue’s environment.

Attackers gained access by exploiting a deprecated service account that still held privileged rights within Klue’s infrastructure, allowing them to harvest OAuth tokens used for the Battlecards integration with Salesforce as reported by Infosecurity Magazine. With those tokens in hand, the threat actor impersonated legitimate users and queried the Salesforce APIs of downstream clients, extracting contact fields such as full name, telephone number and email address. Klue responded by revoking the compromised credential, forcing a reset of all related tokens and engaging CrowdStrike to conduct a forensic review per its public statement. No evidence emerged that the adversaries modified any data or persisted inside the Salesforce organisations.

The intrusion has been claimed by the extortion group Icarus, which posted a list of allegedly affected organisations and threatened to publish the stolen CRM data unless a payment was made by 22 June 2026 per Dark Reading. Victims including Huntress and LastPass have acknowledged that their Salesforce tenants were accessed, though both firms stressed that their core products and services were not altered. Security researchers warn that the harvested contact details increase the risk of highly targeted phishing campaigns and social engineering attempts against employees of the compromised companies.

This incident highlights how weaknesses in third-party SaaS integrations can be leveraged to bypass traditional network defences, especially when OAuth tokens are treated as permanent secrets rather than short-lived credentials as noted in SecurityWeek’s analysis. Organisations that rely on marketplace apps to enrich CRM data must treat those connections as privileged attack surfaces and apply the same rigor used for internal admin accounts. Continuous monitoring of token usage, anomalous login locations and sudden spikes in API calls can help detect abuse before large‑scale exfiltration occurs.

Several cybersecurity vendors have disclosed that their own Klue-linked Salesforce instances were touched, including ReliaQuest, Recorded Future, Jamf and Tanium, while stressing that their platforms and customer data stores remain intact per Infosecurity Magazine. The stolen data primarily consists of business contact information, which could be used to craft convincing lure messages aimed at executives or procurement teams. Affected parties have begun notifying their own customers and advising them to watch for unexpected requests for credentials or financial details.

Defensive steps recommended by incident responders include rotating all OAuth tokens associated with third-party integrations, enforcing multi-factor authentication for any service account that can generate such tokens and applying the principle of least privilege to those accounts as outlined by Huntress. Security teams should also review the list of authorised SaaS apps within their Salesforce org, disable any that are no longer required and enable real-time alerts for consent grants or token issuance from unfamiliar sources. Finally, maintaining up-to-date inventory of vendor-provided credentials and scheduling regular privilege reviews can reduce the window of opportunity for similar supply chain compromises.

Organisations are encouraged to update their incident response playbooks to include scenarios where a trusted vendor’s credential is compromised, ensuring that communication channels with third-party partners are established in advance per the LastPass advisory. Sharing indicators of compromise, such as the specific token values or IP addresses observed during the attack, with industry ISACs can help peers block related activity more quickly. Ongoing user awareness training that stresses the danger of unsolicited messages referencing recent breaches will also lower the likelihood that stolen contact details lead to successful credential theft.

Intelligence briefing updated Jun 24, 2026

Icarus
Root sourceblog.lastpass.com
Timeline Coverage

Swipe to explore timeline