Icarus Group Exploits Klue OAuth Breach to Steal Salesforce Data
Article Content
- •The Icarus group exploited a Klue OAuth breach to steal Salesforce data.
- •Attackers used automated scripts to exfiltrate data over a 24-hour period.
- •Salesforce has disabled the Klue Battlecards integration in response to the breach.
In June 2026, a significant security incident involving Klue, a market intelligence platform, allowed the Icarus threat actor group to exfiltrate Salesforce CRM data from multiple organizations, including Huntress. The attack exploited OAuth tokens from Klue's Battlecards integration, enabling unauthorized access to customer Salesforce instances. The breach began on June 12, 2026, and involved automated scripts that queried Salesforce's REST API for nearly 24 hours, leading to the theft of sensitive CRM data. Salesforce has since disabled the Klue Battlecards integration to mitigate further risks. Both Huntress and ReliaQuest confirmed their data was compromised, and affected organizations are now facing extortion demands from the attackers. The full scope of the impact is still being assessed, but it highlights the vulnerabilities associated with third-party integrations.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (80)
Following this threat?
Track Icarus and Global Retail Brands in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…