Vulnerabilities

Klue OAuth Breach Linked to Icarus

June 18, 2026 16:05 · 12 min read
Klue OAuth Breach Linked to Icarus

Klue OAuth Breach Linked to Icarus Threat Actors

Market intelligence platform Klue suffered a OAuth breach that enabled the 'Icarus' threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign. Sources told BleepingComputer of the attack, stating that numerous organizations had their Salesforce data stolen and were now being extorted by the relatively new extortion group.

Security Incident and Response

Cybersecurity firms ReliaQuest and Huntress have both published reports confirming the security incident, with Huntress stating that their Salesforce data was stolen in the attack. Salesforce has since disabled the Klue Battlecards integration on its platform while the breach is investigated.

"To protect our customers, Salesforce has disabled the connection between the Klue Battlecards app, installed by individual customers, and Salesforce as part of our response to a recent security incident," Salesforce warned. "As a result, organizations will not be able to connect to Salesforce via this app until further notice."

Stolen OAuth Credentials and Data Theft

ReliaQuest stated that attackers gained access to Klue Battlecards integration service accounts and used OAuth tokens associated with customer Salesforce instances to carry out data theft. The researchers observed the threat actors generating OAuth tokens and then using automated Python scripts to query Salesforce's REST API for nearly 24 hours.

The activity began with reconnaissance of an organization's Salesforce instances through the '/services/data/v59.0/sobjects' endpoint before exfiltrating data using the '/services/data/v59.0/query'. ReliaQuest said that for one of the organizations, the attackers slowly mapped out their Salesforce objects to identify valuable objects and then rapidly stole data once they knew what they wanted.

Icarus Extortion Campaign

BleepingComputer learned that the attacks were carried out by a relatively new threat actor known as 'Icarus' who had already begun emailing extortion demands to Klue customers impacted by the breach. A ransom note shared with BleepingComputer showed that the emails were sent using the alias 'mr bean' and included a Session Messenger ID to contact them.

The threat actors' data leak site also contains a message hinting at the extortion campaign in a simple post titled 'Get Ready,' stating, 'big corps getting listed. be ready.' Icarus is believed to have launched in April 2026, and initially listed two victims on its leak site, with BleepingComputer learning that at least one of these victims is connected to the Klue campaign.

Impact and Recommendations

Huntress disclosed that it was among the organizations impacted by the Klue breach, confirming that they had received a similar extortion email as seen by BleepingComputer. The stolen data includes CRM-related information, including business contacts, sales communications, price quotes, competitive intelligence reports, and account data.

Organizations using Klue integrations are advised to review Salesforce and related SaaS logs for activity originating from the listed IP addresses, revoke and rotate OAuth tokens, terminate active sessions, and review Salesforce logs for unusual API activity.

Test every layer before attackers do. Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free