Data Breaches · Supply Chain
Trusted Salesforce Access Became the Blast Radius The breach now sits in customer Salesforce orgs, not just inside Klue. Stolen Klue OAuth tokens let attackers act through a trusted integration, so patching Klue’s side does not undo CRM records already exposed in downstream environments that relied on it.
Multiple security vendors have now confirmed customer data access through the Klue-linked path, and Salesforce has disabled the Klue Battlecards integration. The affected data includes standard CRM records and support-related fields at companies that connected Klue to Salesforce.
Icarus is publicly claiming victims and posting stolen data, which turns this from a vendor compromise into a live disclosure campaign. The broader risk is any SaaS tool that holds standing OAuth access to customer systems; once that token is taken, the customer environment becomes the target.
13 sources · Jun 26
Timeline Sources Jun 26 SecurityWeek
More Klue Breach Victims Identified as Hackers Get Hacked
Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact.
original Jun 25 TechCrunch Security
Hacked Klue says criminals are deleting stolen customer data, but now other hackers are making threats | TechCrunch
Market research company Klue told customers that it believes the hacking group that stole their data is now deleting it.
original Jun 24 Cybersecurity Dive
Klue investigating supply chain attack that targeted Salesforce integrations
Customer data from several prominent cybersecurity firms was among that of hundreds of potential enterprise victims.
original Part of the PlainSec briefing for 2026-06-18
Every edition of this story: Trusted Salesforce Access Became the Blast Radius
Data Breaches · Supply Chain
Trusted Salesforce Access Became the Blast Radius The breach now sits in customer Salesforce orgs, not just inside Klue. Stolen Klue OAuth tokens let attackers act through a trusted integration, so patching Klue’s side does not undo CRM records already exposed in downstream environments that relied on it.
Multiple security vendors have now confirmed customer data access through the Klue-linked path, and Salesforce has disabled the Klue Battlecards integration. The affected data includes standard CRM records and support-related fields at companies that connected Klue to Salesforce.
Icarus is publicly claiming victims and posting stolen data, which turns this from a vendor compromise into a live disclosure campaign. The broader risk is any SaaS tool that holds standing OAuth access to customer systems; once that token is taken, the customer environment becomes the target.
13 sources · Jun 26
Timeline Sources Jun 26 SecurityWeek
More Klue Breach Victims Identified as Hackers Get Hacked
Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact.
original Jun 25 TechCrunch Security
Hacked Klue says criminals are deleting stolen customer data, but now other hackers are making threats | TechCrunch
Market research company Klue told customers that it believes the hacking group that stole their data is now deleting it.
original Jun 24 Cybersecurity Dive
Klue investigating supply chain attack that targeted Salesforce integrations
Customer data from several prominent cybersecurity firms was among that of hundreds of potential enterprise victims.
original Part of the PlainSec briefing for 2026-06-18
Every edition of this story: Trusted Salesforce Access Became the Blast Radius