Klue
Disclosed Jun 19, 20263 months agoConfirmed
Klue legacy credential breach leads to OAuth token theft and Salesforce raids
Competitive intelligence platform Klue said attackers used a legacy 2022 integration credential to steal OAuth tokens connecting to customers' Salesforce environments. The Icarus group claimed the attack, and victims included security firms such as LastPass and 8x8.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jun 19, 2026 |
| Discovered | Jun 12, 2026 |
| Attack | Supply chain |
| Data exposed | Credentials and tokens, API keys, Names, Emails, Messages |
| Sector | Tech · CA |
| Status | Confirmed |
| Part of | Klue (2026) |
Sources
| Source | |
|---|---|
| An update on recent Klue security incidentklue.com · Official notice | Official notice |
| Klue OAuth breach victim list grows as Icarus hackers claim attackbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Jun 19 |
Same campaign
| Organization | Affected | ||||
|---|---|---|---|---|---|
| Jun 233 months ago | Supply chain | Tech | Confirmed | Unknown | |
| Jun 233 months ago | Supply chain | Tech | Confirmed | Unknown |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.