The Hackers Got Hacked: Inside the Klue Breach and What It Means for Every Business Using Cloud Software
A forgotten service account let criminals walk into a competitive-intelligence platform. Then a second criminal group stole the stolen data. The whole chain is a masterclass in how cloud software trust goes wrong.

Key points
- Criminals from a group called Icarus broke into Klue, a Canadian software company serving more than 500 business customers, by using an old forgotten login credential from a pilot project that had never been switched off.
- The attackers did not steal passwords in the traditional sense. Instead they collected OAuth tokens, which are digital passes that let one piece of software speak to another on your behalf, and used them to pull large amounts of customer data from Salesforce, a widely used sales management system.
- A second criminal group then reportedly broke into Icarus and took the already-stolen data, turning the victims into a twice-removed target.
- The root cause was governance, not sophistication: a dormant service account sitting alive in production years after anyone needed it.
- Paying a ransom cannot guarantee data stays private when the criminals holding it may themselves be hacked.
Klue is not a household name. Founded in Vancouver in 2015 and backed by roughly 81 million dollars in venture funding, it makes software that helps sales and marketing teams keep tabs on competitors. More than 500 companies use it. To do its job, Klue plugs into the tools those companies already run: Salesforce, HubSpot, Slack, Google Drive, Gong, SharePoint, Zoom and others.
That access is the whole point of the product. It is also how this breach became everyone's problem, not just Klue's.
How did the attackers get in?
A criminal group called Icarus found a service account, which is a kind of automated login created so one piece of software can talk to another, that had been set up for an old pilot project and never deactivated. Nobody was using it. It was still open.
From there, Icarus did not bother cracking passwords. They harvested OAuth tokens. Think of an OAuth token as a signed permission slip: it tells Salesforce or Slack that Klue is allowed to read your data, without asking for your password every time. Once Icarus held those tokens, they effectively wore Klue's identity inside customer systems.
Over a matter of hours, they ran roughly 1,000 queries in fifteen minutes against at least one customer environment in Salesforce, pulling contact records, pricing details, sales quotes and deal communications. This is the failure mode here: one forgotten credential cascades into a supply-chain event touching hundreds of downstream organisations that had nothing wrong with their own security.
Did a second gang really steal the stolen data?
Yes, reportedly. Icarus told Klue that another criminal group had broken into Icarus's own servers and taken a sample of the already-stolen files. That second group then apparently tried to extort the original victims directly, while also telling those victims not to trust Icarus.
CSO Online, which detailed the incident, describes this as an unusual but strategically important development. Stolen data is not locked in a vault once criminals take it. It circulates. It gets resold. And the people holding it are not always the people you are negotiating with.
The traditional calculation around paying a ransom, which is a demand for money in exchange for criminals promising to delete what they took, assumes one criminal group controls the information. The Klue case shows that assumption can be dead wrong before you ever open negotiations.
What does this mean for ordinary customers?
If your company uses Klue, Salesforce data including contact details, deal notes and pricing records may have been exposed. Klue reportedly detected the intrusion quickly, revoked the stolen credentials and brought in incident-response specialists.
But the downstream reach matters. Because Klue had legitimate, trusted access to customer Salesforce environments, Klue's breach became each customer's breach too, without those customers doing anything wrong.
Practically speaking: if you work somewhere that uses Klue or a similar competitive-intelligence tool, watch for unusual outreach from people who seem to know detailed information about your sales pipeline or pricing. Report anything odd to your security or IT team.
| What happened | Detail |
|---|---|
| Initial access method | Dormant service-account credential from an old pilot project |
| Technique used | OAuth token harvesting, not password theft |
| Data pulled | Salesforce CRM records: contacts, quotes, pricing, deal notes |
| Query volume (one environment) | Approx. 1,000 API queries in 15 minutes |
| Second-breach claim | Icarus reportedly hacked by a separate criminal group who took the stolen data |
| Klue's customer count | 500-plus organisations across North America and Europe |
The one thing the post-mortem will say, and every honest post-mortem in this category says: an inactive credential remained enabled years past its purpose, and nobody had a process to find it.



