FeedThreat IntelligenceKlue OAuth breach linked to 'Icarus' Salesforce data theft a...
Threat IntelligenceBleeping Computer
8.0CRITICAL

Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks

📅 18 June 2026 at 14:19 UTC📰 Bleeping ComputerView original source ↗
Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks

Market intelligence platform Klue suffered a OAuth breach that enabled the "Icarus" threat actors to steal Salesforce CRM data from multiple organizations in an ongoing extortion campaign. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

Klue OAuth breach enabled 'Icarus' threat actors to steal Salesforce CRM data in an ongoing extortion campaign, closely resembling previous Salesforce third-party integration data theft attacks by the ShinyHunters extortion group.

⚙️Technical Details
Affected Systems
Klue Battlecards integration service accountsSalesforce environments
Attack Vectors
OAuth token compromiseMalicious code update
💥Impact Assessment
Severity: high
🛡️Recommended Actions
1Review Salesforce and related SaaS logs for activity originating from the listed IP addresses
2Revoke and rotate OAuth tokens
3Terminate active sessions and review Salesforce logs for unusual API activity
📦Affected Products
Klue Battlecards integrationSalesforce

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer
← Back to feed