Summary

A supply chain attack targeting Klue, a market intelligence platform, has led to the mass exfiltration of Salesforce CRM data from hundreds of enterprise customers — including several prominent cybersecurity companies like LastPass, Recorded Future, BeyondTrust, Tanium, and Huntress. The attack, attributed to a threat actor tracked as “Icarus,” exploited stolen OAuth tokens from a compromised legacy integration credential.

The breach was detected on June 11 when anomalous activity was identified in Klue’s integration infrastructure. By June 13, Klue had revoked OAuth credentials for all customers, disabled integrations, and engaged CrowdStrike for incident response. The attacker used the stolen tokens to authenticate as the Klue integration account and ran automated Python scripts to exfiltrate CRM data via the Salesforce REST API. Icarus has since launched an extortion campaign, giving affected organizations a 48-hour deadline to make contact.

Exfiltrated data includes customer names, emails, physical addresses, phone numbers, support-case data, sales information, and in some cases business contracts and employee contact details. Salesforce has disabled connections through the Klue Battlecards app pending investigation.

Source

Cybersecurity Dive · CSO Online · SecurityWeek

Commentary

The irony of cybersecurity companies getting breached through a third-party SaaS integration is thick, but it underscores a reality the industry has been warning about for years: your security posture is only as strong as your weakest vendor integration. The attack vector — a forgotten legacy credential from a prototype that was never decommissioned — is almost painfully common.

This incident should serve as a wake-up call to audit OAuth tokens and third-party app integrations aggressively. The Klue Battlecards integration had broad read access to CRM data across hundreds of customers, making a single compromised credential devastatingly effective. If you use any third-party Salesforce integrations, now is a good time to review connected apps, rotate tokens, and kill anything you’re not actively using.

By Allan