Salesforce Cuts Klue Battlecards Tie-In After OAuth Token Compromise
The CRM giant pulled the competitive-intelligence app's integration on June 11 following a security incident that exposed connected customer data.

Salesforce has severed its integration with Klue's Battlecards app after the competitive-intelligence vendor suffered a security incident that put customer data accessed through the connector at risk.
The disconnection took effect June 11. Customers cannot reconnect.
In an advisory posted to its trust portal this week, Salesforce said it acted unilaterally to disable the app and is keeping it offline until further notice. The company framed the move as a containment step while Klue investigates.
Klue, based in Vancouver, sells competitive-intelligence software to sales teams. Its Battlecards product pulls deal context out of Salesforce so reps can compare offers against rivals during live opportunities. That pipeline is exactly what attackers appear to have abused.
The incident fits a pattern that has dogged Salesforce customers across 2025 and into 2026: third-party apps with broad OAuth scopes get popped, and the tokens are then replayed to siphon CRM records. Earlier waves hit Salesloft Drift and a string of smaller ISVs, with extortion crews including ShinyHunters and the group tracked as UNC6040 working downstream of the stolen tokens.
It is not yet clear which threat actor compromised Klue, how many tenants were touched, or what categories of records were pulled. Salesforce has not named affected customers. Klue has not published a public incident notice at the time of writing.
What is clear is the access model. OAuth-connected apps like Battlecards hold long-lived refresh tokens scoped to read account, opportunity and contact objects. An attacker holding those tokens can query the API as the app, bypassing MFA and conditional access on the user side. Revocation at the Salesforce edge — which is what disabling the integration accomplishes — is the fastest way to stop the bleeding.
Security teams running Klue should assume their Salesforce data accessible to the Battlecards scope was exposed during the relevant window and treat it accordingly. That means pulling EventLogFile records for the Klue connected app, looking for bulk API queries against Account and Opportunity objects, and reviewing exported data for the period preceding June 11.
Salesforce's own guidance on connected app hygiene recommends restricting OAuth scopes, enforcing IP allowlists at the app level, and rotating consumer secrets on a defined schedule. Few customers do all three.
The broader question is whether the Klue breach is a standalone event or another node in the campaign that has been picking off Salesforce ISVs one by one. Token theft from an upstream SaaS vendor is now the cheapest path into a Fortune 500 CRM. Defenders should price it accordingly.
Threat Vectr has reached out to Klue for comment.



