Klue Breach Compromises Salesforce Data via OAuth Token Theft

Unauthorized access exposes CRM data; threat actors exploit legacy credentials.

ThreatVectr Newsdesk· 2 min read
Klue Breach Compromises Salesforce Data via OAuth Token Theft
Share

Klue, a vendor in competitive intelligence, faces a significant data breach after attackers exploited OAuth tokens to access customer data on platforms such as Salesforce. On June 12, the breach was detected, with Klue CEO Jason Smith addressing the incident publicly on June 19 via the company's blog. The breach involved the use of a compromised legacy credential linked to an abandoned integration service. This led to the unauthorized acquisition of OAuth tokens, enabling the infiltration of several customer environments.

Salesforce identified unusual activity linked to the Klue Battlecards app, prompting the company to disable the integration and prevent reconnection until further notice. In a statement, Salesforce clarified that the issue did not stem from a vulnerability within its own platform. Klue has since taken steps to revoke affected credentials, disable compromised integrations, and inform law enforcement. However, details about the removal and function of unauthorized code remain sparse, with no response from Klue to requests for further clarification.

Huntress, a security vendor affected by the breach, disclosed that the attack involved the deployment of a code update designed to harvest OAuth tokens. This update exploited a credential originally created for a discarded integration project. Attackers then used these tokens to query customer CRM systems, exfiltrating data over approximately 24 hours. ReliaQuest's analysis corroborated this, noting the use of automated scripts to extract CRM data through Salesforce's REST API.

Huntress confirmed data such as business contacts and sales communications were accessed, though no passwords or payment information appeared compromised. Recorded Future, also impacted, reported exposure of client contact details but no evidence of being a targeted victim.

The attack aligns with patterns seen in previous OAuth abuses, yet the attribution to known groups like ShinyHunters remains inconclusive. A new extortion group, Icarus, has claimed responsibility, listing Klue data on a dark-web leak site and suggesting potential further outreach to affected parties. This incident underscores the ongoing risks associated with OAuth integrations, highlighting the need for rigorous token management and monitoring.

© 2026 Threat Vectr