Skip to content

Klue

Disclosed Jun 19, 20263 months agoConfirmed

Official notice

Klue legacy credential breach leads to OAuth token theft and Salesforce raids

Competitive intelligence platform Klue said attackers used a legacy 2022 integration credential to steal OAuth tokens connecting to customers' Salesforce environments. The Icarus group claimed the attack, and victims included security firms such as LastPass and 8x8.

What is known

People affectedNot stated in the sources we have
DisclosedJun 19, 2026
DiscoveredJun 12, 2026
AttackSupply chain
Data exposedCredentials and tokens, API keys, Names, Emails, Messages
SectorTech · CA
StatusConfirmed
Part ofKlue (2026)

Sources

Source
An update on recent Klue security incidentklue.com · Official notice
Klue OAuth breach victim list grows as Icarus hackers claim attackbleepingcomputer.com · News

Notices filed

WhereFiledPeople
ResearchtotalJun 19

Same campaign

OrganizationAffected
8x88x8 says Klue integration abused to exfiltrate Salesforce customer dataJun 233 months agoSupply chainUnknown
LastPassLastPass support case data stolen via Klue OAuth tokensJun 233 months agoSupply chainUnknown
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.

Everything about Klue

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.