1. Executive summary
Between 11–12 June 2026, threat actors compromised market intelligence platform Klue via a legacy credential associated with an integration service, then stole OAuth tokens used to connect Klue to customer third-party platforms (notably Salesforce). Using those tokens, the actors authenticated directly into customer Salesforce instances and exfiltrated business CRM data. At least nine organisations have publicly disclosed impact, including cybersecurity vendors HackerOne, Huntress, Jamf, OneTrust, Recorded Future, Snyk and Tanium, plus Insurity, Sprout Social and revenue-intelligence platform Gong. Stolen data comprises sales account records and business contact information (names, email addresses, job titles, phone numbers, business addresses). A new extortion persona calling itself "Icarus" has claimed the attack on a Tor-based leak site and threatened publication on 22 June; this attribution is unconfirmed and the campaign bears hallmarks of the ShinyHunters/Salesloft/Gainsight pattern. For EMEA financial services firms, the immediate risk is exposure of CRM-resident business contact data and any downstream phishing or social-engineering campaigns targeting those contacts.
2. Regulatory framing
| Article | Trigger (the fact in this item) | Practical impact |
|---|---|---|
| DORA Art. 17 (ICT-related incident management process) | Klue integration compromise triggered exfiltration from customer Salesforce environments on 11–12 June; affected financial entities must run their documented ICT-incident process. | Activate incident response, evidence preservation and lessons-learned workflow for any Klue/Salesforce exposure. |
| DORA Art. 18 (classification of ICT-related incidents and cyber threats) | Exfiltration of business contact data from Salesforce constitutes a classifiable ICT-related incident/cyber threat. | Classify the event against the entity's ICT-incident taxonomy and document severity, impact and root cause. |
| DORA Art. 19 (reporting of major ICT-related incidents to competent authorities) | If classification under Art. 18 yields a "major" ICT-related incident, reporting obligations are triggered. | Assess major-incident thresholds (clients affected, data categories, duration) and prepare initial/ intermediate/ final reports to the competent authority within statutory windows. |
| DORA Art. 28 (ICT third-party risk — general principles) | Klue is an ICT third-party provider; the breach originated in its integration layer. | Re-evaluate third-party risk treatment for Klue and similar integration/BI platforms; ensure register of ICT third-party arrangements is current. |
| DORA Art. 29 (preliminary assessment of ICT concentration risk) | Multiple Klue customers were impacted via a single shared integration, evidencing concentration risk through that provider. | Assess whether the entity has substitutable alternatives; document concentration-risk findings per Art. 29. |
| DORA Art. 30 (key contractual provisions with ICT third-party providers) | Klue's contractual posture (notification, audit, liability, exit) is now under live test following a third-party breach. | Review Klue contract against Art. 30 minimum provisions; trigger contractual remedies and notification tracking. |
| NIS2 Art. 21(2)(d) (supply chain security measures) | Attack is a textbook supply-chain compromise via a BI/integration vendor. | Apply supply-chain security measures proportionate to Klue's role; verify integration scope, token inventory and least-privilege. |
| NIS2 Art. 23 (incident reporting obligations) | In-scope entities (essential/important entities) face incident-reporting duties for incidents having significant impact. | Where the entity is in scope, prepare early warning (within 24h), incident notification (within 72h) and final report per applicable national implementation. |
| UK NIS 2018 (OES/RDSP duties) | UK OES/RDSP using Klue must treat this as a notifiable incident affecting their service. | Apply OES/RDSP incident-response and notification duties under the UK NIS Regulations 2018. |
3. Technical analysis & attack chain
- Initial access — Klue platform. Attacker authenticated to Klue using a compromised legacy credential associated with an integration service (per Klue's own statement and Huntress's write-up).
- Token theft. From that foothold, the actor obtained OAuth tokens that Klue customers had used to authorise the Klue ↔ third-party integration (Salesforce, and potentially Hubspot, Zoom, Google Drive per Risky Bulletin).
- Lateral pivot to customer estates. Tokens were replayed against customer Salesforce (and Gong) environments, bypassing normal interactive authentication and evading customer IP-based controls.
- Data exfiltration. Actors queried and downloaded CRM records — sales account data and business contact information (names, emails, job titles, phone numbers, business addresses). Gong confirmed user names, business titles and emails were accessed but stated no call recordings or transcripts were impacted.
- Containment. Klue revoked affected credentials and tokens, disabled integrations across multiple services, and is working with CrowdStrike and law enforcement. Salesforce disabled the Klue integration; Gong did the same on Friday.
Technical specifics relevant to defenders
- Initial access vector: legacy credential on an integration service — not a software CVE. No CVSS score applies; VERIFIED REFERENCE DATA returned no resolved CVE for this item.
- Vulnerability mechanism: abuse of OAuth token trust model; tokens issued to a first-party integration (Klue) were stolen and replayed against customer tenancies.
- Payload / malware capabilities: none reported. This is a credential-and-token theft operation, not a malware deployment on customer systems.
- Persistence: at the Klue layer via the legacy credential until revocation; at the customer layer via valid OAuth tokens until rotation/disable.
- Privilege escalation: not reported; access was via legitimately scoped OAuth tokens.
- Command-and-control: none reported.
- Lateral movement: token replay into customer Salesforce/Gong tenancies.
- Data access / exfiltration: confirmed exfiltration of CRM business contact data and sales account data; Gong user names/titles/emails.
- Observed impact: nine+ organisations publicly impacted; threat actor has listed victims on a Tor-based leak site and threatened publication on 22 June.
Unconfirmed / single-sourced claims. Attribution to a group calling itself "Icarus" is based on a dark-web leak-site post and Huntress's suggestion; the actor has no MITRE profile in the VERIFIED REFERENCE DATA and the campaign bears the hallmarks of ShinyHunters-style activity (Salesforce, Salesloft Drift, Gainsight). Treat the Icarus attribution as unconfirmed; it may be a persona, an offshoot, or a collaborator. Klue's other integrations (Hubspot, Zoom, Google Drive) are mentioned as in scope of the token theft but no exfiltration from those services has been publicly confirmed.
4. Mitigation & containment
P1 — within 24 hours
- Inventory and rotate. Identify every Klue integration in your Salesforce (and any Hubspot/Zoom/Google Drive/Gong) tenancies. Revoke the Klue OAuth integration and rotate any tokens, refresh tokens and connected-app secrets issued to Klue.
- Audit Salesforce access logs (Event Monitoring / Login History / API logs) for 11–22 June for activity originating from Klue's known IPs/ASNs and from unusual geographies; flag and quarantine sessions that read Account, Contact, Lead, Opportunity records at unusual volumes.
- Disable and re-authorise. Do not merely rotate; remove the Klue connected app and re-onboard only after vendor sign-off and a fresh threat model.
- Blocklist the Klue integration at the CASB/SWG layer pending vendor attestation.
P2 — within 72 hours
- Search for and remove any residual Klue-authored Apex classes, flows, named credentials or connected apps in Salesforce Setup.
- Review Gong (if used) for evidence of access to user records; rotate Gong-issued credentials and revoke any Klue-mediated tokens.
- Engage Klue contractually under DORA Art. 30: demand written notification, root-cause report, and confirmation of token revocation across all customers.
- Concentration-risk review (DORA Art. 29): document whether Klue is a single point of failure for any revenue-intelligence or competitive-intelligence workflow.
P3 — within 7 days
- Third-party risk reassessment (DORA Art. 28): re-score Klue; require SOC 2 / ISO 27001 evidence covering the integration service that was compromised.
- Supply-chain hardening (NIS2 Art. 21(2)(d)): enforce least-privilege OAuth scopes, IP-based conditional access for connected-app callbacks, short-lived tokens, and just-in-time access for any BI/integration vendor.
- Customer-comms readiness: prepare breach-notification text for any business contacts whose data was exfiltrated, in line with GDPR Art. 33/34 thresholds and DORA Art. 19 reporting.
5. Indicators of compromise
No technical IOCs (file hashes, C2 domains, IPs, registry keys, commands) are present in the source material. The only attributable artefact is the threat actor's Tor-based leak site, which is not named or linked in the sources.
| Type | Value | Confidence | Source |
|---|---|---|---|
| actor-alias | "Icarus" (Tor leak-site post claiming responsibility) | Low — unconfirmed attribution | SecurityWeek / Huntress |
No indicators of compromise available in the source material.
6. Detection
Insufficient indicators to author detection rules.
The source material contains no file hashes, C2 domains/IPs, distinctive strings, command-line flags, mutex names, scheduled-task or service names, registry keys, ransom-note text, or hard-coded values from which to build a YARA or Sigma rule. Authoring a rule on inferred artefacts would risk false positives.
7. Sources
- SecurityWeek — More Cybersecurity Firms Disclose Impact From Klue Hack — https://www.securityweek.com/more-cybersecurity-firms-disclose-impact-from-klue-hack/ — 22 Jun 2026
- SecurityWeek — Cybersecurity Firms Impacted by Klue Supply Chain Attack — https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/ — Jun 2026
- Risky Business News — Risky Bulletin: Klue breach impacts security firms — https://news.risky.biz/risky-bulletin-klue-breach-impacts-security-firms/ — Jun 2026
- Help Net Security — Klue breach lead to Salesforce data theft, Huntress affected — https://www.helpnetsecurity.com/2026/06/19/klue-salesforce-data-breach-huntress/ — 19 Jun 2026
- DataBreaches.net — Klue OAuth breach victim list grows as Icarus hackers claim attack — https://databreaches.net/2026/06/21/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/ — 21 Jun 2026
- BleepingComputer — Klue OAuth breach victim list grows as Icarus hackers claim attack — https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/ — Jun 2026
8. Adverse Trace position
Severity: Moderate (data-exfiltration supply-chain incident, not a software CVE). No CVSS score applies; VERIFIED REFERENCE DATA returned no resolved CVE for this item. The risk to EMEA financial services clients is twofold: (1) direct exposure of CRM-resident business contact data for any client using Klue's Salesforce/Gong integrations, and (2) downstream phishing/social-engineering risk against those contacts, particularly given the ShinyHunters-style tradecraft. Attribution to "Icarus" remains unconfirmed. Next steps: monitor Klue's investigation output and CrowdStrike's findings; track whether additional Klue integrations beyond Salesforce are confirmed exfiltrated; reassess if technical IOCs (C2, hashes) emerge that enable detection rules; and update this advisory if any financial-sector client is publicly named.
Published via PulseTrace — Adverse Trace threat intelligence.