Salesforce Cuts Klue Battlecards Tie-In After OAuth Token Compromise
The CRM giant pulled the competitive-intelligence app's integration on June 11, 2026 following a security incident that exposed connected customer data.

Key points
- Salesforce disabled the Klue Battlecards integration on June 11, 2026 after a security incident at the competitive-intelligence vendor.
- Customers cannot reconnect until further notice.
- Attackers holding OAuth refresh tokens can query the Salesforce API as the app, bypassing MFA on the user side.
- Neither Salesforce nor Klue has named affected customers or quantified exposed records.
- Security teams should pull EventLogFile records for the Klue connected app and audit bulk API queries against Account and Opportunity objects.
What happened to the Klue Battlecards integration?
Salesforce disabled the Klue Battlecards app on June 11, 2026 after a security incident at Klue compromised the OAuth tokens the app uses to connect to customer Salesforce orgs. Salesforce posted an alert to its trust portal this week confirming it acted unilaterally and is keeping the integration offline while Klue investigates. Customers cannot reconnect.
Klue, based in Vancouver, sells competitive-intelligence software to sales teams. Its Battlecards product pulls deal context from Salesforce so reps can compare offers against rivals during live opportunities. That pipeline is what attackers appear to have abused.
How does OAuth token abuse work here?
OAuth-connected apps like Battlecards hold long-lived refresh tokens scoped to read account, contact and opportunity records. An attacker with those tokens can query the API as the application, sidestepping MFA and conditional-access controls tied to individual user accounts. Revoking the integration at the Salesforce edge is the fastest way to cut off that access, which is exactly what Salesforce did.
We've tracked this pattern closely: our 3 June report on ShinyHunters' Canvas LMS breach showed how peripheral SaaS connectors become entry points that compliance reviews rarely reach, and our 28 May story on the Kali365 phishing kit documented how stolen OAuth tokens let attackers bypass MFA without touching a user's password.
It isn't yet clear which threat actor compromised Klue, how many tenants were affected, or what categories of records were pulled. Earlier waves hitting Salesforce ISVs have involved groups including ShinyHunters, but no attribution has been made in this case.
Should you worry if you ran Klue Battlecards?
Yes. If your org had Battlecards connected, treat any Salesforce data within that app's scope as potentially exposed. Pull EventLogFile records for the Klue connected app, look for bulk API queries against Account and Opportunity objects, and review exported data for the period before June 11.
Salesforce's own guidance on connected app hygiene recommends restricting OAuth scopes, enforcing IP allowlists at the app level, and rotating consumer secrets on a schedule. Few customers do all of that.
What does this mean for the broader SaaS supply chain?
Token theft from an upstream SaaS vendor is now among the cheapest paths into a large enterprise CRM. The Klue incident may be isolated, but it may also be another node in a campaign that has been picking off Salesforce ISVs. Defenders should price that risk accordingly. Klue hasn't published a public incident notice as of writing, and Threat Vectr has reached out for comment.



