Klue Confirms OAuth Token Theft as 'Icarus' Crew Stakes Public Claim
The market intelligence vendor's disclosure adds another name to the lengthening list of Salesforce-adjacent SaaS breaches tied to stolen OAuth credentials.

Klue, the Vancouver-based competitive and market intelligence platform, has confirmed that attackers stole OAuth tokens used to connect the service to customer Salesforce tenants. A newly surfaced extortion group calling itself Icarus is publicly claiming the intrusion.
The disclosure is brief on specifics. Klue says the tokens were exfiltrated from its environment and then used to reach into downstream Salesforce orgs belonging to its customers. The vendor has notified affected organizations directly.
This is the pattern regulators have been watching all year.
OAuth grants sit awkwardly in the disclosure framework. They are neither credentials in the traditional sense nor a vulnerability in the issuing platform — they are delegated trust, and when a SaaS integrator is compromised, that trust travels. For public companies, the question of whether a third-party token theft triggers a Form 8-K Item 1.05 "material cybersecurity incident" filing turns on impact to the registrant, not on where the token was stored. The SEC's adopting release made that distinction explicit when the final rule took effect in December 2023.
Klue is privately held and not itself subject to Item 1.05. Its customers may be.
The Icarus group's public claim adds a second pressure vector. Extortion crews increasingly publish victim lists to force disclosure timelines, a tactic that collides with the four-business-day clock that begins on a materiality determination. Counsel at affected downstream firms will need to decide quickly whether a third-party token compromise touching their Salesforce data meets the threshold.
The broader campaign context matters. A string of 2024 and 2025 incidents has involved OAuth tokens issued to SaaS connectors — sales enablement tools, CRM enrichment platforms, analytics integrators — being abused to pull Salesforce object data at scale. The common thread is not a Salesforce flaw. It is the long-lived, broadly scoped refresh token sitting inside a third party.
For regulated entities, two compliance hooks are worth flagging now:
- CIRCIA reporting. CISA's proposed rule under the Cyber Incident Reporting for Critical Infrastructure Act, published at 89 Fed. Reg. 23644 (April 4, 2024), would require covered entities to report substantial cyber incidents within 72 hours. The proposed rule expressly contemplates third-party-enabled compromises. The comment period closed July 3, 2024; a final rule is expected in 2025.
- NIS2 supply-chain obligations. Article 21(2)(d) of Directive (EU) 2022/2555 requires essential and important entities to address supply-chain security, including direct supplier relationships. EU customers of Klue with NIS2 obligations should be assessing whether this incident triggers notification under Article 23.
Klue has not published indicators of compromise or a timeline of token issuance and revocation. Customers should rotate any remaining tokens, audit Salesforce login history and connected app records, and preserve logs in anticipation of regulatory inquiry.
The Icarus brand is new. The playbook is not.



