Klue confirms OAuth token theft in breach linked to Icarus group

Market intelligence platform Klue confirmed a security breach leading to OAuth token theft, now claimed by the Icarus extortion group.

By Central
Klue acknowledged OAuth token theft via compromised credentials, impacting multiple Salesforce customer instances.
Highlights
  • The breach was detected on June 12, exploiting a compromised legacy credential linked to an integration service.
  • Icarus extortion group claimed responsibility, pressuring Klue and affected organizations via Session messaging.
  • Affected organizations include Recorded Future, Tanium, Jamf, and others, with data stolen from Salesforce instances.

Market intelligence platform Klue has formally acknowledged a security breach that led to the theft of OAuth tokens used to connect with customers’ Salesforce environments, an incident now publicly claimed by the newly identified Icarus extortion group. The disclosure, confirmed by Klue CEO Jason Smith, reveals that the attack leveraged a compromised legacy credential associated with an integration service, enabling the threat actor to steal authorization tokens and subsequently access data within multiple connected customer instances of Salesforce.

Breach Timeline and Initial Discovery

Klue detected unauthorized activity on June 12, affecting a portion of its integration infrastructure. The company immediately initiated an investigation, engaged CrowdStrike for incident response, and began working with external cybersecurity experts. According to Smith, the attacker gained access through a compromised legacy credential related to an integration service. This access was then used to obtain OAuth tokens that facilitate connections between Klue and third-party platforms, most notably Salesforce.

The investigation confirmed that the attacker used the stolen tokens to access data within a number of connected customer Salesforce environments. Klue has stated that there is currently no evidence indicating that customer content stored directly within the Klue platform was compromised, limiting the scope of the incident to the third-party integrations.

How the Attack Unfolded: OAuth Token Abuse and Data Exfiltration

Cybersecurity firms Huntress and ReliaQuest, who independently investigated the breach, provided detailed technical analysis of the attack methodology. ReliaQuest observed the attackers generating OAuth tokens and deploying Python scripts to query Salesforce’s API over extended periods, systematically extracting CRM data. Huntress confirmed that its own Salesforce instance was among those affected, with stolen data including business contacts, sales communications, pricing information, and other critical business records.

The attack vector underscores a growing threat in the SaaS ecosystem: the abuse of delegated authentication credentials. By compromising a single integration service credential, the attackers were able to pivot into multiple downstream customer environments, effectively amplifying the scope of a single breach.

Icarus Extortion Group Steps Forward

The Icarus extortion group, previously linked to the operation by BleepingComputer and Huntress, has now publicly claimed responsibility on its data leak site. In a post, the group stated, “As you’ve probably already heard, Klue.com has been impacted by us recently. A number of other companies’ Salesforce instances, which were partners to Klue, were exfiltrated.” The threat actors are pressuring Klue and affected organizations to contact them through the Session messaging platform to prevent the public release of stolen data.

Huntress independently connected the operation to Icarus by matching Session Messenger IDs used in extortion emails with identifiers on the group’s data leak site. Since the initial reports, a growing list of victims has come forward, including Recorded Future, Tanium, Jamf, Sprout Social, Gong, and Insurity. Almost all affected organizations have confirmed that the incident led to the theft of data from their Salesforce instances but did not impact their own platforms, payment systems, or internal infrastructure.

The Broader Implications for Third-Party Risk

This incident highlights a critical vulnerability in modern enterprise ecosystems: the cascading risk of third-party integrations. When a platform like Klue holds OAuth tokens that grant access to partner systems, a single compromise can expose multiple organizations to data theft. Several affected organizations have warned that the stolen business contact information could fuel follow-on phishing, social engineering, and extortion campaigns, urging customers to remain vigilant.

What Affected Users and Organizations Should Do Now

For any organization that uses Klue or similar integration services, immediate action is required. First, review and rotate all OAuth tokens and credentials associated with third-party integrations, especially those connected to Salesforce. Enable detailed logging for API access to detect unusual query patterns or extended data extraction periods. Deploy a robust security monitoring solution that can detect anomalous OAuth token usage, and implement strict access controls on integration services that limit the scope of delegated permissions.

For individual users whose data may have been exposed in downstream Salesforce instances, remain alert for targeted phishing or social engineering campaigns that leverage stolen business contact information. Use a reputable, no-logs VPN service when accessing corporate networks remotely to add an additional layer of encryption and anonymity. Monitor accounts for any signs of unauthorized access and enable multi-factor authentication on all sensitive platforms immediately.

Share This Article