The market intelligence platform Klue has fallen victim to a security breach orchestrated by a newly identified extortion group calling itself Icarus. The attackers compromised Klue's systems to steal OAuth tokens, which they then used to gain unauthorized access to the integrated Salesforce CRM environments of Klue's customers. This incident is a stark example of a SaaS-to-SaaS (Software-as-a-Service) attack, where the trust relationship between two cloud applications is exploited. The attackers bypassed conventional login mechanisms by using the stolen tokens to make legitimate API calls, allowing them to silently exfiltrate sensitive customer data from Salesforce. This highlights the critical need for stringent auditing and monitoring of third-party application permissions and API activity.
The attack on Klue and its customers demonstrates a sophisticated understanding of modern cloud application architecture. The threat actor, Icarus, did not need to compromise individual user passwords for Salesforce. Instead, they targeted the authorization mechanism that connects the two platforms.
OAuth is an open standard for access delegation, commonly used to grant applications access to user data on other web services without giving them the passwords. In this case, Klue customers had granted the Klue application a token to access their Salesforce data. The Icarus group compromised Klue's environment and stole these pre-authorized tokens. With a valid token, the attacker's requests to the Salesforce API appear to be legitimate requests coming from the Klue application, making the malicious activity difficult to detect.
The attack chain follows a modern cloud-native pattern:
This attack vector is particularly dangerous because it abuses a legitimate and necessary function of integrated cloud applications. It bypasses user-facing security controls like MFA and relies on compromising the 'machine' identity (the OAuth token) rather than a 'human' identity.
The business impact of this breach is significant for Klue's customers:
For Klue, the impact includes severe reputational damage, potential legal liability, and the high cost of incident response and remediation.
Detection:
GET requests, requests for data types not typically accessed by the integration, or activity originating from unusual IP ranges (if the attacker is not proxying through the original vendor's infrastructure). This is a form of User Behavior Analysis applied to machine identities.Response:
Immediate Actions:
Strategic Improvements:
Klue breach details emerge: initial access via legacy credential, Gong also impacted, and specific high-profile victims like Huntress and Recorded Future named. Incident detected June 11.
New details reveal the Klue supply chain breach originated from a compromised legacy credential, allowing attackers to inject malicious code and harvest OAuth tokens. The Icarus group used these tokens to access not only Salesforce but also Gong environments of customers. High-profile victims now include Huntress, Recorded Future, Tanium, Jamf, Sprout Social, and Insurity. The incident was detected on June 11, 2026, highlighting the cascading risks in interconnected SaaS ecosystems and the need for robust credential management. The report also provides specific cyber observables for detection.
LastPass disclosed a breach originating from the Klue compromise, where stolen OAuth tokens were used to access its Salesforce customer data.
Password manager LastPass has disclosed that it was also impacted by the Klue supply chain attack. Attackers leveraged the previously stolen OAuth tokens from Klue to gain unauthorized access to LastPass's Salesforce environment, compromising customer data. This development significantly increases the scope and impact of the original incident, adding a high-profile victim and further emphasizing the cascading risks of third-party integrations and OAuth token compromise.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.