Cybertech Europe 2026-IT Industry Official Media Partner
Subscribe

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
Contact us

Klue confirms breach – Icarus behind attacks on Salesforce customers

Klue and Salesforce after security breach where Icarus exploited stolen OAuth tokens to access customer data Klue and Salesforce after security breach where Icarus exploited stolen OAuth tokens to access customer data
Illustration of the security incident where attackers exploited stolen OAuth tokens to access Salesforce environments via Klue integrations.

Market intelligence platform Klue has confirmed a security incident in which attackers obtained OAuth tokens used to connect customers’ Salesforce environments, while a new ransomware group, Icarus, has claimed responsibility for the attacks.

The incident came to light after cybersecurity companies Huntress and ReliaQuest published analyses showing how attackers exploited compromised integrations between Klue and Salesforce to steal data from multiple organizations.

In a statement published this week, Klue CEO Jason Smith confirmed that the company detected unauthorized activity on June 12 which affected parts of the company's integration infrastructure.

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

– On June 12, we identified unauthorized activity that impacted a portion of our integration infrastructure. Since then, we have been working with cybersecurity experts to understand what happened, support our customers, and restore the connections that customers rely on, says Jason Smith.

According to the company's investigation, the attackers gained access through compromised legacy login credentials linked to an integration service.

The attackers were then able to come over OAuth token which was used to connect Klue to various third-party platforms, including Salesforce. This gave them the ability to access information across multiple customers’ connected environments.

Klue states that there is currently no indication that customer data stored directly on Klue's own platform has been affected. The incident is said to be limited to third-party integrations, according to the company.

The company says it immediately revoked affected credentials and tokens, removed unauthorized code, disabled affected integrations, launched an internal investigation, and contacted relevant authorities. Klue has also engaged CrowdStrike to assist in the ongoing investigation.

Data theft via Salesforce

Both ReliaQuest and Huntress have determined that the attackers used stolen OAuth credentials linked to Klue's integrations to gain access to customers' Salesforce-environments and carry out extensive data theft.

ReliaQuest observed how the attackers generated OAuth tokens and used Python scripts to make API calls to Salesforce over extended periods of time while exfiltrating information.

Huntress later confirmed that its own Salesforce system was also affected by the incident. The stolen information included business contacts, sales communications, pricing information, and other business-related data.

Icarus claiming responsibility for the Klue breach

Icarus takes responsibility

While both BleepingComputer and Huntress previously linked the attacks to the Icarus ransomware group, the group has now publicly claimed responsibility via its leak site.

In a message, the group writes that Klue has been affected by their attack and that several Salesforce instances at companies connected to it Clue has been exfiltrated.

Icarus also urges Klue and the affected organizations to contact the group via the messaging platform Session to prevent the stolen information from being published.

Previous reports have shown that ransomware was sent to affected companies. Huntress was also able to link the attacks to Icarus through identifiers used in Session and information on the group's leak site.

More companies confirm impact

Since the incident became known, several organizations have confirmed that they were affected by the attacks, including Recorded Future, Tanium, Jamf, Sprout Social, Gong and Insurance.

Almost all companies state that the breach resulted in data being stolen from their Salesforce environments, but that their own platforms, internal systems, payment solutions, and other infrastructures were not affected.

Several of the organizations are now warning that the stolen business information could be used in future phishing campaigns, social engineering and extortion attempts. Customers and partners are therefore urged to be extra vigilant about suspicious emails and contact attempts.

The incident is another example of the risks that can arise when third-party integrations gain extensive access to business-critical systems. Security experts are now recommending that companies regularly review OAuth permissions, restrict access levels, and monitor integrations that have access to sensitive business information.

What does this mean for Swedish companies?

The Klue incident shows how third-party integrations and OAuth permissions can create significant security risks for Swedish companies. Many organizations use Salesforce, CRM platforms and cloud services along with external applications for sales, marketing and business analytics.

When a third-party provider is compromised, attackers can gain access to sensitive business information without the main platform itself being compromised. The incident underscores the importance of continuously reviewing connected applications, API permissions, and OAuth tokens.

What does this mean for Swedish security teams?

Identities, APIs, and third-party integrations have become one of the biggest attack surfaces in modern cloud environments. Security teams need to monitor OAuth permissions, analyze unusual API calls, and regularly review which external applications have access to business systems.

Principles such as Zero Trust, multi-factor authentication, least privilege, and continuous identity monitoring are becoming increasingly important to reduce the risk of similar incidents.

Risks and opportunities

Compromised OAuth tokens can give attackers access to customer data, CRM information, business communications, and strategic tasks, while increasing the need for identity security, API protection, cloud security, and advanced threat monitoring.

Organizations that implement continuous monitoring of SaaS environments and third-party integrations can more quickly detect anomalous activity and limit the damage in the event of an incident.

Salesforce and SaaS Security

Salesforce is used by thousands of companies worldwide for customer relationships, sales, and business processes. The Klue incident shows that third-party applications with extensive OAuth permissions can pose a significant security risk even if the CRM platform itself has not been compromised.

Businesses are advised to regularly review connected apps, restrict permissions, revoke inactive tokens, and monitor API traffic.

Cyber extortion and new threat actors

Icarus represents a new generation of cybercriminal groups that combine data theft, extortion, and public exposure of stolen information. Modern attacks increasingly target supply chains, cloud services, and SaaS platforms.

Data theft has become a key tool for extortion groups that use sensitive business information to blackmail affected organizations.

What does this mean for Salesforce users?

Organizations that use Salesforce with external services should conduct security audits of all integrations. Regular audits of OAuth permissions and third-party apps can reduce the risk of unauthorized access.

Monitoring API activity and identity-based attacks is becoming an important part of modern security strategies.

Related topics

Salesforce security, OAuth security, SaaS security, identity security, cloud security, API security, CRM security, cyberthreats Sweden, cybersecurity Sweden, corporate security, data breach, cyber resilience, information security, threat intelligence, zero trust, social engineering, phishing, attack surface management.

Global supplier signals

Salesforce, CrowdStrike, Huntress, ReliaQuest, Microsoft Security, Google Cloud Security, Okta, Palo Alto Networks, Cisco Security, Fortinet, Splunk, SentinelOne, IBM Security, identity protection, cloud security operations and enterprise cybersecurity.

Google Discover and AI search optimization

Klue breach, Salesforce attack, OAuth token theft, Icarus cyberattack, Salesforce data breach, CRM security, SaaS security, cyber extortion, cloud security, identity security, enterprise cybersecurity, API security, cyber resilience, cybersecurity news, security operations.

What does this mean for Swedish companies?

Swedish companies are becoming increasingly dependent on cloud services, identity platforms and external integrations. The incident shows that security is no longer just about networks and servers, but also about identities, APIs and third-party providers.

What does this mean for MSPs in the Nordics?

While the incident does not directly target the MSP market, service providers responsible for customers' Salesforce environments, identity management, and cloud security are affected. Security monitoring of SaaS platforms is becoming a growing service area.

Risks and opportunities

Organizations that invest in identity security, API protection, and continuous monitoring of third-party integrations can reduce the risk of future data breaches and strengthen their cyber resilience.

IT channel, tech magazine, Swedish IT news site, Nordic IT media, IT news financial sector, cyberthreat banks Nordics, cyber report finance Sweden, IT security news Sweden, Nordic cybersecurity media, enterprise IT security Nordics, b2b IT media Sweden, cybersecurity report Sweden.

Stay up to date with the most important news

By pressing the Subscribe button, you confirm that you have read and agree to our privacy policy and terms of use
  • VORTIQ-X AI Governance helps companies transform AI into controllable and verifiable business value.
    VORTIQ-X is an AI Governance platform that helps organizations govern, verify, and create measurable business value from AI. The platform focuses on transparency, compliance, AI governance, and the effective use of AI in mission-critical processes.
    ADVERTISEMENT

  • Maciek Szczesniak featured on IT-Branschen Wire Channel Magic Chats podcast banner
    Maciek Szczesniak appears on IT-Branschen Wire Channel Magic Chats, discussing leadership, innovation, digital transformation, and business services.
    SPONSORED

  • The IT industry Nordic technology media platform covering cybersecurity, cloud, AI, digital transformation, channel, MSP and enterprise IT news
    The IT industry is a leading Nordic technology media platform covering cybersecurity news, artificial intelligence, cloud computing, enterprise IT, digital transformation, managed services, channel partners, software development, telecommunications, data centers, IT infrastructure, technology leadership, business innovation, and emerging technologies. Through executive interviews, industry analysis, event coverage, thought leadership, product launches, vendor updates, and market insights, the IT industry connects technology decision-makers, CIOs, CISOs, CTOs, IT managers, MSPs, resellers, distributors, technology vendors, startups, and enterprise organizations across Sweden, Norway, Denmark, Finland, and Europe. Coverage includes cybersecurity trends, AI adoption, cloud strategy, enterprise software, networking, digital infrastructure, sustainability, compliance, governance, risk management, automation, data analytics, and future technology developments.
    OWN CONTENT

  • Cybertech Europe 2026 cybersecurity conference in Rome with the IT industry as Official Media Partner
    Cybertech Europe 2026 is one of Europe's leading cybersecurity conferences, bringing together cybersecurity leaders, government officials, technology innovators, startups, investors, and enterprise decision-makers in Rome. The IT industry serves as an Official Media Partner, providing event coverage, executive interviews, industry insights, and cybersecurity news for Nordic and European audiences.
    ADVERTISEMENT