Market intelligence platform Klue has confirmed a security incident in which attackers obtained OAuth tokens used to connect customers’ Salesforce environments, while a new ransomware group, Icarus, has claimed responsibility for the attacks.
The incident came to light after cybersecurity companies Huntress and ReliaQuest published analyses showing how attackers exploited compromised integrations between Klue and Salesforce to steal data from multiple organizations.
In a statement published this week, Klue CEO Jason Smith confirmed that the company detected unauthorized activity on June 12 which affected parts of the company's integration infrastructure.
– On June 12, we identified unauthorized activity that impacted a portion of our integration infrastructure. Since then, we have been working with cybersecurity experts to understand what happened, support our customers, and restore the connections that customers rely on, says Jason Smith.
According to the company's investigation, the attackers gained access through compromised legacy login credentials linked to an integration service.
The attackers were then able to come over OAuth token which was used to connect Klue to various third-party platforms, including Salesforce. This gave them the ability to access information across multiple customers’ connected environments.
Klue states that there is currently no indication that customer data stored directly on Klue's own platform has been affected. The incident is said to be limited to third-party integrations, according to the company.
The company says it immediately revoked affected credentials and tokens, removed unauthorized code, disabled affected integrations, launched an internal investigation, and contacted relevant authorities. Klue has also engaged CrowdStrike to assist in the ongoing investigation.
Data theft via Salesforce
Both ReliaQuest and Huntress have determined that the attackers used stolen OAuth credentials linked to Klue's integrations to gain access to customers' Salesforce-environments and carry out extensive data theft.
ReliaQuest observed how the attackers generated OAuth tokens and used Python scripts to make API calls to Salesforce over extended periods of time while exfiltrating information.
Huntress later confirmed that its own Salesforce system was also affected by the incident. The stolen information included business contacts, sales communications, pricing information, and other business-related data.

Icarus takes responsibility
While both BleepingComputer and Huntress previously linked the attacks to the Icarus ransomware group, the group has now publicly claimed responsibility via its leak site.
In a message, the group writes that Klue has been affected by their attack and that several Salesforce instances at companies connected to it Clue has been exfiltrated.
Icarus also urges Klue and the affected organizations to contact the group via the messaging platform Session to prevent the stolen information from being published.
Previous reports have shown that ransomware was sent to affected companies. Huntress was also able to link the attacks to Icarus through identifiers used in Session and information on the group's leak site.
More companies confirm impact
Since the incident became known, several organizations have confirmed that they were affected by the attacks, including Recorded Future, Tanium, Jamf, Sprout Social, Gong and Insurance.
Almost all companies state that the breach resulted in data being stolen from their Salesforce environments, but that their own platforms, internal systems, payment solutions, and other infrastructures were not affected.
Several of the organizations are now warning that the stolen business information could be used in future phishing campaigns, social engineering and extortion attempts. Customers and partners are therefore urged to be extra vigilant about suspicious emails and contact attempts.
The incident is another example of the risks that can arise when third-party integrations gain extensive access to business-critical systems. Security experts are now recommending that companies regularly review OAuth permissions, restrict access levels, and monitor integrations that have access to sensitive business information.








