Breaches · 82 days ago
The break is in the app trust layer, not Salesforce itself. Once Klue’s OAuth tokens were stolen, the attacker could reach customer data through every connected org that had granted that access, so one vendor breach became parallel exposure across multiple tenants.
More companies have now disclosed compromise, including Huntress, LastPass, HackerOne, Recorded Future, Jamf, Snyk, OneTrust, Insurity, Tanium, and Sprout Social. LastPass said its products and infrastructure were not affected, and Gong said some customers using the Klue integration may also have had internal licensed user data exposed, including usernames, titles, and emails.
Icarus is publicly warning that more victims are still coming. The risk now sits in standing third-party grants and tokens, which can keep working until they are revoked, across Salesforce and any other system the same app can reach.
3 sources covering this story
BeyondTrust, LastPass Impacted by Klue-Salesforce Incident
Over a dozen Klue customers have confirmed that hackers stole data from their Salesforce instances.
LastPass customer data exposed through Klue supply chain attack - Help Net Security
LastPass disclosed a data breach after attackers used stolen Klue OAuth tokens to access Salesforce customer records and customer data.
Scope of Salesforce Attacks Expands as Icarus Leaks Data
More victims have emerged after attackers breached application vendor Klue and used its OAuth tokens to steal customers' Salesforce data.
Part of the PlainSec briefing for 2026-06-24