BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Salesforce disables Klue app after data breach

Klue breach via legacy credential exposes customer data through stolen OAuth tokens

  • Security firm Klue suffered a breach via a legacy credential, allowing hackers to steal OAuth tokens and access customer data on integrated platforms.
  • The incident led Salesforce to disable the Klue Battlecards app integration, confirming the issue originated from the app’s connection, not its own platform.
  • Cyber extortion group Icarus compromised sales-related data from customers like Huntress, demanding contact within 48 hours.
  • The attack methodology mirrors previous third-party OAuth token abuses targeting CRM systems, highlighting a persistent security gap.
  • Klue has revoked affected tokens and launched an investigation, directly assisting impacted customers.

Salesforce disabled the Klue Battlecards app integration on June 11, 2026, after detecting unusual activity that exposed customer data, according to an alert published this week. The cloud software giant stated the security incident was limited to the app’s connection and not a vulnerability within its own platform.

- Advertisement -

Consequently, organizations cannot connect to Salesforce via the app until further notice. The company noted the action was taken because the activity may have resulted in unauthorized access to customer data.

Meanwhile, the extortion group Icarus claimed responsibility for compromising Klue and exfiltrating data from its customers. Cybersecurity company Huntress confirmed its sales-related data was copied from its Salesforce account. Huntress said the breach did not affect threat data, passwords, or payment card information.

Klue’s CEO, Jason Smith, explained the attackers gained access through a compromised legacy credential on June 12. He said the intruders used that access to obtain OAuth tokens connecting Klue to third-party platforms like Salesforce.

Subsequently, the threat actors pushed a code update to collect these tokens and directly query customer CRM tools. By June 16, some Huntress employees received emails from Icarus demanding communication within 48 hours regarding the stolen data.

- Advertisement -

Security researchers have linked this attack to a known third-party OAuth-abuse playbook. ReliaQuest analysts Thassanai McCabe and Alexa Feminella said the adversary ran automated Python scripts for bulk data retrieval over nearly 24 hours.

Klue has since revoked the affected credentials and tokens while removing unauthorized code. The company is assisting impacted customers directly as the investigation continues.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Bitcoin Microtransactions Hit Record, 80% of Daily Network Activity

Transactions below 0.01 BTC now represent roughly 80% of daily Bitcoin network activity, nearly...

Yuan Gains in Africa as $400 Billion Trade Shifts From Dollar

The Chinese yuan is gaining significant ground in African trade settlements, challenging the US...

BlackRock’s Bitcoin ETF Lures New Investors to Entire ETF Market

BlackRock's spot Bitcoin ETF has attracted a significant number of first-time ETF investors.Many of...

Audit Gap Exposed As AI Finds Major Four-Year Crypto Bug

A critical four-year-old bug in ZCash's shielded pool, discovered in June 2026, wiped out...

Z.ai’s GLM-5.2 Nears Claude Opus, Beats GPT-5.5, MIT Licensed

Z.ai released the GLM-5.2 AI model, which performs within 1% of Claude Opus 4.8...

Must Read

Top 10 Best Blockchain Games

If you want to know about the best blockchain games then read this article carefully. We listed the best games you can play and...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading