Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
A recent breach at Klue, a market intelligence platform, allowed the "Icarus" threat actor to steal Salesforce CRM data from multiple organizations, triggering an ongoing extortion campaign. The attackers leveraged stolen OAuth credentials and automated scripts to access Salesforce instances and exfiltrate sensitive data, including customer contacts and sales information. Salesforce responded by disabling the Klue Battlecards integration, and cybersecurity firms like ReliaQuest and Huntress have confirmed the impact, highlighting the potential for data compromise and extortion.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data