threat-intel
Salesforce Disables Klue App Integration After OAuth Token Abuse Exposes Customer Data
High
Summary
Salesforce disabled the Klue Battlecards app integration following a security incident where the Icarus extortion group exploited compromised credentials to access customer data via Salesforce. The attackers leveraged a legacy credential to steal OAuth tokens, enabling them to query connected customer environments and exfiltrate business contacts and price quotes. Huntress, a cybersecurity company, was impacted, receiving a threatening email demanding payment. The incident highlights the risks associated with third-party integrations and the abuse of OAuth tokens.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
