The breach now sits in customer Salesforce orgs, not just inside Klue. Stolen Klue OAuth tokens let attackers act through a trusted integration, so patching Klue’s side does not undo CRM records already exposed in downstream environments that relied on it.
Multiple security vendors have now confirmed customer data access through the Klue-linked path, and Salesforce has disabled the Klue Battlecards integration. The affected data includes standard CRM records and support-related fields at companies that connected Klue to Salesforce.
Icarus is publicly claiming victims and posting stolen data, which turns this from a vendor compromise into a live disclosure campaign. The broader risk is any SaaS tool that holds standing OAuth access to customer systems; once that token is taken, the customer environment becomes the target.
Klue says hackers stole credential from 2022 that led to customer data breaches | TechCrunch
It's unclear why Klue had not revoked the credential after the limited pilot, which hackers then used to breach a system holding keys for accessing customers' data.