Trusted Salesforce Access Became the Blast Radius

The breach now sits in customer Salesforce orgs, not just inside Klue. Stolen Klue OAuth tokens let attackers act through a trusted integration, so patching Klue’s side does not undo CRM records already exposed in downstream environments that relied on it. Multiple security vendors have now confirmed customer data access through the Klue-linked path, and Salesforce has disabled the Klue Battlecards integration. The affected data includes standard CRM records and support-related fields at companies that connected Klue to Salesforce. Icarus is publicly claiming victims and posting stolen data, which turns this from a vendor compromise into a live disclosure campaign. The broader risk is any SaaS tool that holds standing OAuth access to customer systems; once that token is taken, the customer environment becomes the target.

Part of the PlainSec briefing for 2026-06-27

Sources