Klue OAuth Breach Expands as Icarus Hackers Claim Salesforce Data Theft

Jun 23, 2026

Threat Actors Exploit OAuth Tokens to Access Salesforce Data

Market intelligence platform Klue has confirmed a security incident that allowed threat actors to steal OAuth tokens connected to customer Salesforce environments. The breach has now expanded as the threat group known as "Icarus" publicly claimed responsibility and began naming alleged victims on its extortion portal.

According to reports, attackers abused a compromised legacy credential tied to a dormant prototype integration. This allowed them to obtain OAuth tokens and use them to access connected Salesforce instances without requiring user passwords or bypassing multifactor authentication.

Security firms investigating the incident observed attackers querying Salesforce environments at scale, extracting sensitive business information from affected organizations. Klue stated that the incident was contained and that the compromised credential was revoked after discovery.

Incident Overview

Category

Details

Incident Type

OAuth Token Theft / SaaS Data Breach

Affected Platform

Klue

Threat Actor

Icarus

Initial Access

Compromised legacy integration credential

Targeted Systems

Salesforce environments connected to Klue

Data Accessed

Business contacts, sales communications, quotes, competitive intelligence

Authentication Bypassed

OAuth token abuse (no password required)

Discovery Date

June 2026

Status

Contained and under investigation

How the Attack Worked

The attackers reportedly gained access to a legacy credential associated with an unused prototype integration. Using that credential, they were able to retrieve OAuth tokens that granted access to connected Salesforce customer environments.

Because OAuth tokens serve as trusted authorization mechanisms, possession of a valid token can provide access to cloud resources without requiring the account password. Once authenticated, the threat actors allegedly performed extensive API queries against Salesforce environments to collect customer data.

Investigators observed activity patterns consistent with large-scale data collection, including repeated API requests against customer records and sales-related datasets.

Data Potentially Exposed

Klue and investigators indicate that the compromised data may include:

  • Business contact information

  • Customer relationship records

  • Internal sales communications

  • Pricing and quote information

  • Competitive intelligence reports

  • Salesforce account data linked to Klue integrations

The company stated that passwords, payment card information, and direct authentication credentials were not exposed as part of the incident.

Icarus Claims the Attack

Following public disclosure of the incident, the threat actor known as Icarus claimed responsibility and began listing alleged victims on its extortion infrastructure. The group has been active throughout 2026 and has been associated with multiple data theft and extortion campaigns targeting SaaS platforms and cloud-connected environments.

As is common in modern extortion operations, attackers are attempting to pressure affected organizations into negotiations by threatening to leak stolen data publicly. At the time of reporting, investigations into the full scope of impacted organizations remain ongoing.


Why OAuth-Based Attacks Are Increasing

OAuth integrations simplify access between cloud applications but can create significant security risks when tokens or integration credentials are compromised.

Unlike passwords, OAuth tokens often:

  • Remain valid for extended periods

  • Operate with broad permissions

  • Allow API access without interactive login

  • Can bypass traditional password-reset protections

Threat actors increasingly target third-party SaaS integrations because compromising a single integration can provide access to multiple downstream customer environments.

Recommended Mitigation Steps

Organizations using SaaS integrations should take the following actions:

1. Audit OAuth Applications

Review all connected OAuth applications and remove unused or legacy integrations.

2. Rotate Integration Credentials

Immediately rotate credentials associated with third-party integrations and service accounts.

3. Monitor API Activity

Implement monitoring for unusual API requests, excessive data exports, and suspicious access patterns.

4. Enforce Least Privilege

Limit OAuth scopes and permissions to only the resources necessary for business operations.

5. Review Third-Party Risk

Continuously assess vendors and SaaS providers that maintain access to corporate systems and data.

6. Establish Token Revocation Procedures

Ensure security teams can rapidly revoke OAuth tokens during incident response activities.

Key Takeaway

The Klue breach highlights how attackers are increasingly targeting OAuth integrations rather than traditional user credentials. By compromising a single integration credential, the Icarus threat group allegedly gained access to Salesforce-connected environments and valuable business data across multiple organizations.

As SaaS ecosystems continue to expand, organizations must treat OAuth tokens and third-party integrations as highly privileged assets, applying the same level of monitoring, access control, and incident response preparedness used for traditional credentials.

Latest News

Klue OAuth Breach Expands as Icarus Hackers Claim Salesforce Data Theft

Klue OAuth Breach Expands as Icarus Hackers Claim Salesforce Data Theft

Klue OAuth Breach Expands as Icarus Hackers Claim Salesforce Data Theft

Klue OAuth Breach Expands as Icarus Hackers Claim Salesforce Data Theft

Klue OAuth Breach Expands as Icarus Hackers Claim Salesforce Data Theft

Jun 23, 2026

Rokarolla Android Banking Trojan Targets 217 Banking and Crypto Apps

Rokarolla Android Banking Trojan Targets 217 Banking and Crypto Apps

Rokarolla Android Banking Trojan Targets 217 Banking and Crypto Apps

Rokarolla Android Banking Trojan Targets 217 Banking and Crypto Apps

Rokarolla Android Banking Trojan Targets 217 Banking and Crypto Apps

Jun 17, 2026

Microsoft June 2026 Patch Tuesday Fixes 200 Vulnerabilities and 3 Zero-Days

Microsoft June 2026 Patch Tuesday Fixes 200 Vulnerabilities and 3 Zero-Days

Microsoft June 2026 Patch Tuesday Fixes 200 Vulnerabilities and 3 Zero-Days

Microsoft June 2026 Patch Tuesday Fixes 200 Vulnerabilities and 3 Zero-Days

Microsoft June 2026 Patch Tuesday Fixes 200 Vulnerabilities and 3 Zero-Days

Jun 10, 2026

ChatGPT Share Links Abused to Deliver Malware Through Fake OpenAI Outage Pages

ChatGPT Share Links Abused to Deliver Malware Through Fake OpenAI Outage Pages

ChatGPT Share Links Abused to Deliver Malware Through Fake OpenAI Outage Pages

ChatGPT Share Links Abused to Deliver Malware Through Fake OpenAI Outage Pages

Jun 3, 2026

GlassWorm Botnet Disrupted After Resilient C2 Infrastructure Takedown

GlassWorm Botnet Disrupted After Resilient C2 Infrastructure Takedown

GlassWorm Botnet Disrupted After Resilient C2 Infrastructure Takedown

GlassWorm Botnet Disrupted After Resilient C2 Infrastructure Takedown

GlassWorm Botnet Disrupted After Resilient C2 Infrastructure Takedown

May 28, 2026

Ghost CMS SQL Injection Flaw Exploited in Massive ClickFix Campaign

Ghost CMS SQL Injection Flaw Exploited in Massive ClickFix Campaign

Ghost CMS SQL Injection Flaw Exploited in Massive ClickFix Campaign

Ghost CMS SQL Injection Flaw Exploited in Massive ClickFix Campaign

Ghost CMS SQL Injection Flaw Exploited in Massive ClickFix Campaign

May 26, 2026

Get updates in your inbox directly

You are now subscribed.

Get updates in your inbox directly

You are now subscribed.

Get updates in your

inbox directly

You are now subscribed.

Get updates in your inbox directly

You are now subscribed.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.

Enable your employees as first line of defense and expand your digital footprints without any fear.