threat-intel
Salesforce Data Thefts Continue via Klue App Compromise
High
Summary
A series of data thefts targeting Salesforce instances have been linked to a new threat actor group, Icarus, following a compromise of Klue's Battlecards app. The attacks leveraged compromised OAuth tokens and Python scripts to exfiltrate customer data, including sales contacts and price quotes, mirroring previous breaches involving third-party SaaS integrations. This incident highlights the ongoing risk posed by vulnerabilities in trusted SaaS integrations and the need for robust monitoring of data access.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
