Klue Token Theft Spreads Beyond One Salesforce Tenant
The break is in the app trust layer, not Salesforce itself. Once Klue’s OAuth tokens were stolen, the attacker could reach customer data through every connected org that had granted that access, so one vendor breach became parallel exposure across multiple tenants.
More companies have now disclosed compromise, including Huntress, LastPass, HackerOne, Recorded Future, Jamf, Snyk, OneTrust, Insurity, Tanium, and Sprout Social. LastPass said its products and infrastructure were not affected, and Gong said some customers using the Klue integration may also have had internal licensed user data exposed, including usernames, titles, and emails.
Icarus is publicly warning that more victims are still coming. The risk now sits in standing third-party grants and tokens, which can keep working until they are revoked, across Salesforce and any other system the same app can reach.