Breaches · 80 days ago
The breach now sits in customer Salesforce orgs, not just inside Klue. Stolen Klue OAuth tokens let attackers act through a trusted integration, so patching Klue’s side does not undo CRM records already exposed in downstream environments that relied on it.
Multiple security vendors have now confirmed customer data access through the Klue-linked path, and Salesforce has disabled the Klue Battlecards integration. The affected data includes standard CRM records and support-related fields at companies that connected Klue to Salesforce.
Icarus is publicly claiming victims and posting stolen data, which turns this from a vendor compromise into a live disclosure campaign. The broader risk is any SaaS tool that holds standing OAuth access to customer systems; once that token is taken, the customer environment becomes the target.
13 sources covering this story
More Klue Breach Victims Identified as Hackers Get Hacked
Roughly two dozen companies have notified their customers of the Klue-Salesforce incident impact.
Market research company Klue told customers that it believes the hacking group that stole their data is now deleting it.
Klue says hackers stole credential from 2022 that led to customer data breaches | TechCrunch
It's unclear why Klue had not revoked the credential after the limited pilot, which hackers then used to breach a system holding keys for accessing customers' data.
This is the second data breach to affect LastPass customers in recent years, after one of the password manager's tech partners was recently breached.
Klue investigating supply chain attack that targeted Salesforce integrations
Customer data from several prominent cybersecurity firms was among that of hundreds of potential enterprise victims.
LastPass confirms data breach in Klue supply chain attack
LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in the Klue supply chain attack earlier this month.
Lessons from the Klue incident | Snyk
Lessons learned from the Klue breach and how it applies to everyone.
Security shops among the 'hundreds' of Klue hack victims
As yet another extortion crew Icarus exploits Salesforce-linked integrations
Risky Bulletin: Klue breach impacts security firms
A data breach at business analytics platform Klue spreads to security firms, a hacker breaches Brazil's national alert system, North Korea [Read More
Klue hack results in data breach at several cybersecurity firms | TechCrunch
Huntress, HackerOne, Jamf, Recorded Future, and Tanium are among the cybersecurity companies that had data stolen following an earlier breach at market research firm Klue.
Klue breach exposed Salesforce CRM data through stolen OAuth tokens
Cybersecurity firms were among those caught up in the breach.
Klue Breach Enables Hackers to Compromise Cybersecurity Firms
At least four cybersecurity firms confirmed they have been affected by a breach of business intelligence platform Klue via Salesforce integration
Part of the PlainSec briefing for 2026-06-27