1. Executive summary
Market intelligence platform Klue has confirmed a security incident in which attackers abused a compromised legacy credential tied to an integration service to steal OAuth tokens used to connect Klue to customer environments — most consequentially Salesforce. At least eight downstream organisations have confirmed impact, including cybersecurity vendors Huntress, ReliaQuest, Recorded Future, HackerOne, Jamf, OneTrust, Snyk and Tanium, with exfiltration of Salesforce-resident data confirmed. A previously unobserved group calling itself "Icarus" has claimed responsibility via a dark-web leak site and is attempting to extort both Klue and the downstream victims directly. The campaign bears the operational hallmarks of prior ShinyHunters-linked activity against Salesforce, Salesloft-Drift and Gainsight; the "Icarus" persona is currently unconfirmed as an independent actor. For EMEA financial services firms, the immediate risk is any Klue integration (Salesforce, Hubspot, Zoom, Google Drive) holding client, deal or PII data, and any third-party SaaS connector model that re-uses long-lived OAuth tokens.
2. Regulatory framing
| Article | Trigger (fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 17 — ICT-related incident management process | Klue is an ICT third-party provider; the incident requires a documented incident management response by affected financial entities. | Activate ICT incident response runbook; evidence-trail all containment, eradication and recovery actions. |
| DORA Art. 18 — classification of ICT-related incidents and cyber threats | Salesforce-resident data exfiltration from multiple financial-sector-adjacent vendors requires formal classification against ICT-related incident criteria. | Classify severity, document criteria applied, retain classification rationale for competent-authority review. |
| DORA Art. 19 — reporting of major ICT-related incidents to competent authorities | Confirmed data exfiltration from production SaaS integrations may meet "major" thresholds once impact is quantified. | Prepare initial notification within statutory window; submit intermediate and final reports per the timeline. |
| DORA Art. 28 — ICT third-party risk — general principles | Klue is an ICT third-party service provider whose compromise propagates risk into regulated entities. | Re-evaluate Klue in the third-party register; document risk treatment and exit/ contingency options. |
| DORA Art. 29 — preliminary assessment of ICT concentration risk | Multiple Klue customers in the financial-services supply chain share the same integration surface. | Assess whether Klue represents a concentration risk; record findings and mitigations. |
| DORA Art. 30 — key contractual provisions with ICT third-party providers | Klue's incident triggers review of contractual notification, audit and liability clauses. | Invoke vendor notification clauses; assess audit, sub-contractor and liability provisions. |
| NIS2 Art. 21(2)(d) — supply chain security measures | The incident is a supply-chain compromise propagating from a SaaS integration provider. | Apply supply-chain security controls to the Klue relationship and any analogous long-lived OAuth integrations. |
| NIS2 Art. 23 — incident reporting obligations | Confirmed exfiltration of customer data from in-scope entities triggers incident reporting duties. | File early warning and incident notification per national CSIRT timelines. |
| UK NIS 2018 — OES/RDSP duties | UK OES/RDSPs using Klue or affected integrations must treat this as a relevant incident. | Notify the relevant UK competent authority and record the incident under OES/RDSP duties. |
3. Technical analysis & attack chain
- Initial access — credential compromise. Attackers obtained a "compromised legacy credential associated with an integration service" inside Klue's platform. Klue has not disclosed the specific service, account or credential type; treat the precise vector as unconfirmed.
- Token theft. From the compromised integration foothold, the attackers stole OAuth tokens that Klue customers had used to authorise Klue's integrations with third-party SaaS platforms (Salesforce, Hubspot, Zoom, Google Drive and others).
- Lateral pivot into customer estates. Attackers used the stolen tokens to authenticate to customer Salesforce orgs (and potentially other integrated SaaS) under the legitimate Klue integration identity, bypassing normal user authentication.
- Data discovery and exfiltration. Once authenticated, attackers enumerated and downloaded Salesforce-resident data. Huntress and ReliaQuest detected anomalous data-access patterns and outbound activity originating from the Klue integration principal.
- Extortion stage. A group self-styled "Icarus" posted a claim on its dark-web leak site over the weekend, attempting to extort Klue and warning downstream victims to contact them directly or face data publication.
Technical specifics relevant to defenders
- Integration surface: Klue's documented integrations include Salesforce, Hubspot, Zoom and Google Drive. Salesforce is the primary target because it is where sensitive financial and PII data is typically aggregated.
- Token model: Long-lived OAuth tokens issued to Klue's integration service. These tokens are bearer credentials and inherit the full permission scope granted by the customer at authorisation time.
- Detection signal: Anomalous data-access volume and outbound exfiltration originating from the Klue integration principal inside customer Salesforce orgs. Huntress and ReliaQuest publicly cited this behavioural pattern as their trigger.
- Containment action taken by Klue: Revocation of credentials, tokens and active integrations; engagement of CrowdStrike for forensic support.
- Victim set (confirmed to date): Klue, HackerOne, Huntress, Jamf, OneTrust, Recorded Future, ReliaQuest, Snyk, Tanium. Victim list is expected to grow as Klue notifies additional customers.
Unconfirmed / single-sourced claims. The "Icarus" persona has no MITRE ATT&CK profile and no prior public track record; treat attribution to a new independent group as unconfirmed. The campaign's TTPs (OAuth-token theft from a SaaS integration, downstream Salesforce exfiltration, dark-web extortion) are consistent with the ShinyHunters playbook previously observed against Salesforce, Salesloft-Drift and Gainsight; "Icarus" may be a rebrand, an offshoot or a collaborator rather than a genuinely new actor. No CVE, no malware sample, no specific IP/domain/hash and no exploit mechanism beyond "compromised legacy credential" has been disclosed at the time of writing.
4. Mitigation & containment
P1 — within 24 hours
- Inventory Klue exposure. Identify every Klue integration (Salesforce, Hubspot, Zoom, Google Drive, others) in use across the estate; record the OAuth app name, client ID, scopes and authorised user.
- Revoke and rotate. Revoke all Klue-issued OAuth tokens and refresh tokens for the affected integrations; force re-authorisation through a controlled flow.
- Audit Salesforce (and other) logs for activity originating from the Klue integration principal between the earliest known compromise window and now. Look for unusual SOQL query volume, report exports, bulk API calls, and data egress to non-corporate IPs.
- Blocklist the Klue integration at the IdP/Salesforce connected-app level pending re-validation; require step-up MFA for any re-authorisation.
- Engage Klue under contractual notification clauses (DORA Art. 30) and request forensic indicators, scope of compromise and notification timeline.
P2 — within 72 hours
- Review all long-lived OAuth integrations (not only Klue) for analogous risk: tokens older than 90 days, broad scopes, no IP/geo restriction, no rotation policy. Apply principle of least privilege and shorten token lifetimes.
- Tighten connected-app policy in Salesforce: enforce IP restrictions, restrict API access by profile, enable "Block API access for non-trusted IPs" where feasible, and require admin approval for connected apps.
- Threat-hunt for the same TTPs across other SaaS (Hubspot, Zoom, Google Drive) where Klue tokens may have been issued.
- Vendor risk re-assessment of Klue under DORA Art. 28 / 29; document concentration-risk findings.
P3 — within 7 days
- Contractual review of Klue and similar integration providers against DORA Art. 30 provisions (notification SLAs, audit rights, sub-contractor controls, liability).
- Tabletop exercise scoped to OAuth-token compromise of a critical SaaS integration; validate DORA Art. 17 incident management process end-to-end.
- Permanent policy change: mandate OAuth token rotation cadence, scope minimisation at authorisation, and continuous monitoring of integration-principal behaviour.
5. Indicators of compromise
No indicators of compromise available in the source material.
6. Detection
Insufficient indicators to author detection rules.
7. Sources
- DataBreaches.net — "Klue OAuth breach victim list grows as Icarus hackers claim attack" — https://databreaches.net/2026/06/21/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/ — 2026-06-21
- BleepingComputer — "Klue OAuth breach victim list grows as Icarus hackers claim attack" — https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/ — 2026-06-21
- Risky Business News — "Risky Bulletin: Klue breach impacts security firms" — https://news.risky.biz/risky-bulletin-klue-breach-impacts-security-firms/ — 2026-06-21
- SecurityWeek — "Cybersecurity Firms Impacted by Klue Supply Chain Attack" — https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ — 2026-06-21
- Help Net Security — "Klue breach lead to Salesforce data theft, Huntress affected" — https://www.helpnetsecurity.com/2026/06/19/klue-salesforce-data-breach-huntress/ — 2026-06-19
- SecurityWeek — "More Cybersecurity Firms Disclose Impact From Klue Hack" — https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/ — 2026-06-21
8. Adverse Trace position
Severity: High. Confirmed exfiltration of customer data from production Salesforce estates via a trusted third-party integration, with the victim list still expanding, places this in the high-impact band for any EMEA financial services firm using Klue or holding regulated data in Salesforce. Attribution to "Icarus" is unconfirmed and the actor's TTPs are consistent with the established ShinyHunters playbook, so defensive planning should not assume a new, less-capable adversary. We will continue to monitor for additional victim disclosures, any IOCs released by Klue/CrowdStrike, and any further claims from the Icarus leak site, and will update this advisory with concrete detection content as soon as usable artefacts are published.
Published via PulseTrace — Adverse Trace threat intelligence.