> ## Content Index
> Fetch the complete content index at: https://f4n6.co.uk/llms.txt
> Use this file to discover other available public pages before exploring further.

# Scope of Salesforce Attacks Expands as Icarus Leaks Data
- URL: https://f4n6.co.uk/security-feed/scope-of-salesforce-attacks-expands-as-icarus-leaks-data/
- Published: 2026-06-24T09:15:35.000Z
- Updated: 2026-06-24T09:15:35.000Z
- Author: Jeff Davies
- Tags: #security-feed, Icarus

## 1\. Executive summary

Market intelligence platform Klue disclosed on 19 June 2026 that an attacker obtained OAuth tokens used to connect Klue to customer Salesforce environments, after gaining access via a compromised legacy credential associated with a Klue integration service. The intrusion occurred on 11 June 2026 and was detected one day later. Multiple cybersecurity vendors — including Huntress, Recorded Future, ReliaQuest, Tanium, Jamf, Gong, HackerOne, Kudelski Security, Snyk, Insurity and Sprout Social — have confirmed their Salesforce CRM data was accessed. A previously unobserved extortion group calling itself "Icarus" has claimed the attack on its data-leak site and is contacting affected organisations directly. The bottom-line risk for EMEA financial services firms is unauthorised disclosure of CRM-resident business contacts, quotes and sales correspondence where Klue is integrated with Salesforce; no passwords, payment card data or core product telemetry are reported as compromised. Attribution to "Icarus" is currently unconfirmed — the group has no MITRE ATT&CK profile and the campaign TTPs resemble prior ShinyHunters-style OAuth abuse against Salesforce.

## 2\. Regulatory framing

| Article                                                                          | Trigger (fact in this item)                                                                                                                                                          | Practical impact                                                                                                                                  |
| -------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------- |
| DORA Art. 28 — ICT third-party risk — general principles                         | Klue is an ICT third-party provider whose integration service was compromised, exposing customer Salesforce data.                                                                    | Reassess third-party risk register entries for Klue; document the incident and the controls now in place (token revocation, credential rotation). |
| DORA Art. 29 — preliminary assessment of ICT concentration risk                  | Klue serves more than 250,000 companies; firms using Klue for Salesforce enrichment may have a concentration point.                                                                  | Determine whether Klue is a critical or important ICT service provider supporting CRM workflows and, if so, evaluate substitutability.            |
| DORA Art. 30 — key contractual provisions with ICT third-party providers         | Klue has disconnected all integrations (Salesforce, Gong, HubSpot, SharePoint, Google Drive) and engaged CrowdStrike; contractual notification and audit rights are now in play.     | Review Klue contract for notification SLAs, audit rights, exit assistance and liability; trigger formal vendor risk review.                       |
| DORA Art. 17 — ICT-related incident management process                           | A confirmed third-party-driven incident affecting customer Salesforce data requires a documented incident management response.                                                       | Activate the firm's ICT incident management process; record detection, containment, eradication and recovery steps.                               |
| DORA Art. 18 — classification of ICT-related incidents and cyber threats         | The incident must be classified against the firm's ICT incident taxonomy (e.g. data exfiltration via third-party OAuth token abuse).                                                 | Apply classification criteria; document severity, scope and impact.                                                                               |
| DORA Art. 19 — reporting of major ICT-related incidents to competent authorities | If, after classification, the incident is determined to be major (significant CRM data exposure, multiple affected clients, reputational impact), reporting obligations are engaged. | Prepare initial notification within the applicable reporting window once classification is complete.                                              |
| NIS2 Art. 21(2)(d) — supply chain security measures                              | Klue sits in the supply chain between the firm and Salesforce; the compromise demonstrates a supply-chain vector.                                                                    | Verify supply-chain security measures (vendor due diligence, integration scoping, token hygiene) cover integration-service providers.             |
| NIS2 Art. 23 — incident reporting obligations                                    | If the firm is in scope and the incident meets the significant-impact threshold, early warning and incident notification obligations apply.                                          | Prepare early warning within the early-warning window and follow-up notification per the applicable timeline.                                     |
| UK NIS 2018 — OES/RDSP duties                                                    | UK operators of essential services or relevant digital service providers using Klue for CRM enrichment must consider incident-handling duties.                                       | UK in-scope entities should review their competent-authority notification duties under the UK NIS Regulations 2018.                               |

## 3\. Technical analysis & attack chain

1. **Initial access — legacy credential at integration service.** On 11 June 2026, an attacker used a compromised legacy credential associated with a Klue integration service to obtain OAuth tokens used to connect Klue to third-party platforms, including Salesforce (per Klue CEO Jason Smith's blog post).
2. **Token theft.** The attacker used the integration-service foothold to obtain OAuth tokens for Klue's Salesforce (and other) integrations.
3. **Pivot to customer environments.** Using the stolen tokens, the attacker authenticated to customer Salesforce environments and accessed CRM data. Huntress and ReliaQuest observed the activity and notified Klue.
4. **Detection.** Klue detected the unauthorised activity on 12 June 2026, one day after initial access.
5. **Containment by vendor.** Klue disconnected all integrations with Salesforce, Gong, HubSpot, SharePoint and Google Drive; revoked credentials, tokens and active integrations; engaged CrowdStrike for investigation and response.
6. **Extortion phase.** A group calling itself "Icarus" (active since 28 April 2026 per its leak-site entry) began emailing affected customers directly. Huntress shared an extortion email with subject line **"top secret email"** purportedly sent from **"mr bean"**, instructing the recipient to contact the attackers via Session messenger and threatening publication of stolen data within 48 hours.

### Technical specifics relevant to defenders

- **Component abused:** Klue integration service (vendor-side) and the OAuth tokens it held for customer Salesforce integrations. No specific CVE is associated with this incident; the vector is credential and token abuse, not a software vulnerability.
- **Data scope observed:** Business contacts, price quotes, sales-related data and messaging. Huntress explicitly states no threat data, passwords, payment card information or engineering data relating to its agent/telemetry was affected. Huntress and other victims state there is no indication their products or infrastructure were compromised — the impact is specific to CRM data.
- **TTP parallels:** ReliaQuest notes the campaign "resembles the 2025 and 2026 third-party OAuth abuse campaigns against Salesforce." The activity is distinct from prior ShinyHunters operations against Salesforce, Salesloft Drift and Gainsight, although Risky Business flags the possibility that "Icarus" is a fake persona, offshoot or collaborator of ShinyHunters.
- **Extortion tradecraft:** Use of Session messenger for contact, short (48-hour) deadlines, direct victim contact in addition to the leak-site posting.

**Unconfirmed / single-sourced claims.** Attribution to "Icarus" is unconfirmed: the group has no MITRE ATT&CK profile and the extortion email's poor grammar and misspellings are consistent with multiple unaffiliated actors. The hypothesis that "Icarus" is a ShinyHunters offshoot or collaborator is analyst speculation from Risky Business, not corroborated by primary evidence.

## 4\. Mitigation & containment

### P1 — within 24 hours

- **Inventory exposure.** Identify any business unit, subsidiary or vendor using Klue Battlecards or any other Klue integration with Salesforce. Confirm whether Klue has notified your organisation as a customer.
- **Rotate Salesforce credentials and API keys** for any user, service account or integration that interacted with Klue data, including any OAuth refresh tokens issued to Klue.
- **Revoke and reissue OAuth tokens** for any Klue-related Salesforce connected app; force re-consent.
- **Audit Salesforce audit logs and Event Monitoring** (if licensed) for the period 11 June 2026 to date for: logins from unfamiliar ASNs/IPs, mass record reads, report exports, API calls originating from Klue integration IPs, and any session originating from outside expected geographies.
- **Block known Klue integration IPs** at the WAF/proxy if Klue publishes them; otherwise restrict Salesforce API traffic to allow-listed sources until tokens are rotated.
- **Search mailboxes** for the extortion email subject "top secret email" and the sender display name "mr bean"; quarantine and report any matches to the incident response team. Do not engage.

### P2 — within 72 hours

- **Review Salesforce connected apps** and remove any Klue-related app that is no longer required; re-authorise only after a documented risk assessment.
- **Enable Salesforce IP restrictions, MFA and session-based permissions** for all CRM users; verify least-privilege profiles for sales/CRM roles.
- **Engage Klue** in writing to obtain: scope of tokens compromised, list of customer environments accessed, timeline of attacker activity, and confirmation that all Klue-side tokens have been revoked.
- **Vendor risk review** under DORA Art. 28/30: trigger formal review of Klue as an ICT third-party provider; document compensating controls and exit options.
- **Concentration-risk assessment** under DORA Art. 29: determine whether Klue is a critical or important service provider for CRM workflows and document substitutability.

### P3 — within 7 days

- **Tabletop exercise** covering third-party OAuth token abuse scenarios; validate incident classification (DORA Art. 18) and reporting readiness (DORA Art. 19 / NIS2 Art. 23).
- **Contractual remediation:** request from Klue post-incident report, root-cause analysis, and contractual undertakings on token storage, rotation cadence and integration-service authentication hardening.
- **Threat-model update:** add "integration-service legacy credential compromise" as a documented scenario; review other vendors with similar integration patterns (Gong, HubSpot, SharePoint, Google Drive, Zoom) for the same exposure.
- **User awareness brief** to sales/CRM teams on the extortion email pattern and the Session-messenger contact vector.

## 5\. Indicators of compromise

| Type                         | Value                                               | Confidence | Source                                            |
| ---------------------------- | --------------------------------------------------- | ---------- | ------------------------------------------------- |
| email-subject                | top secret email                                    | high       | Huntress extortion email shared with The Register |
| email-sender-display-name    | mr bean                                             | high       | Huntress extortion email shared with The Register |
| messaging-channel            | Session messenger (address not disclosed in source) | high       | Huntress extortion email shared with The Register |
| dark-web-leak-site           | Icarus data-leak site (URL not disclosed in source) | medium     | The Register / Risky Business                     |
| incident-date-initial-access | 2026-06-11                                          | high       | Klue CEO blog post via The Register               |
| incident-date-detection      | 2026-06-12                                          | high       | Klue CEO blog post via The Register               |

```iocs
email-subject  top secret email
email-sender-display-name  mr bean
messaging-channel  Session messenger
incident-date-initial-access  2026-06-11
incident-date-detection  2026-06-12

```

## 6\. Detection

```yara
rule AT_2026_06_24_Klue_OAuth_Extortion_Email
{
    meta:
        author = "Adverse Trace"
        date = "2026-06-24"
        description = "Detects extortion email content associated with the Klue/Salesforce OAuth token theft campaign attributed (unconfirmed) to 'Icarus'."
        reference = "https://www.theregister.com/cyber-crime/2026/06/22/security-shops-among-the-hundreds-of-klue-hack-victims/5259743"

    strings:
        $subj = "top secret email"
        $sender = "mr bean"
        $klue = "Klue.com" ascii nocase
        $salesforce = "Salesforce" ascii nocase
        $session = "Session @" ascii nocase
        $exfil = "exfiltrated" ascii nocase
        $breach = "breach" ascii nocase

    condition:
        3 of ($subj, $sender, $klue, $salesforce, $session, $exfil, $breach)
}

```

```yaml
title: Klue OAuth Token Abuse Against Salesforce (Klue supply-chain incident)
id: at-2026-06-24-klue-oauth
status: experimental
description: |
  Detects anomalous OAuth-token-driven access to Salesforce originating from
  Klue integration infrastructure following the 11 June 2026 Klue compromise.
  Hunt for unusual API/connected-app activity against Salesforce instances
  that previously integrated with Klue.
author: Adverse Trace
date: 2026-06-24
references:

  - https://www.theregister.com/cyber-crime/2026/06/22/security-shops-among-the-hundreds-of-klue-hack-victims/5259743
logsource:
  product: salesforce
  service: event_monitoring
detection:
  selection_api_burst:
    EventType|contains:

      - "API"
      - "ConnectedApp"
    Application|contains:

      - "Klue"
    Uri|endswith:

      - "/services/data"
      - "/services/oauth2"
  selection_unusual_source:
    EventType: "Login"
    Application|contains: "Klue"
    LoginType: "Application"
  condition: selection_api_burst or selection_unusual_source
falsepositives:

  - Legitimate Klue integration activity prior to 11 June 2026
  - Scheduled Klue data syncs (validate against known schedules)
level: high

```

## 7\. Sources

- Dark Reading — Scope of Salesforce Attacks Expands as Icarus Leaks Data — https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data (23 Jun 2026)
- BleepingComputer — Klue OAuth breach victim list grows as Icarus hackers claim attack — https://www.bleepingcomputer.com/news/security/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
- DataBreaches.net — Klue OAuth breach victim list grows as Icarus hackers claim attack — https://databreaches.net/2026/06/21/klue-oauth-breach-victim-list-grows-as-icarus-hackers-claim-attack/
- The Register — Security shops among the 'hundreds' of Klue hack victims — https://www.theregister.com/cyber-crime/2026/06/22/security-shops-among-the-hundreds-of-klue-hack-victims/5259743
- Risky Business — Risky Bulletin: Klue breach impacts security firms — https://news.risky.biz/risky-bulletin-klue-breach-impacts-security-firms/
- Snyk — When a vendor's breach becomes yours: lessons from the Klue incident — https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/
- SecurityWeek — Cybersecurity Firms Impacted by Klue Supply Chain Attack — https://www.securityweek.com/cybersecurity-firms-impacted-by-klue-supply-chain-attack/

## 8\. Adverse Trace position

**Severity: Moderate.** This is a third-party-driven CRM data exposure with no reported compromise of products, infrastructure, passwords or payment data; however, the affected data (business contacts, quotes, sales correspondence) is commercially sensitive and the supply-chain pattern matches prior high-impact OAuth abuse campaigns against Salesforce. Attribution to "Icarus" remains unconfirmed — the group has no MITRE ATT&CK profile and the campaign TTPs overlap with ShinyHunters-style activity, so we treat the actor label as a working hypothesis rather than a confirmed attribution. EMEA financial services clients using Klue-integrated Salesforce should treat this as a P1 vendor incident: rotate tokens and credentials within 24 hours, audit Salesforce logs for the 11 June 2026 to present window, and trigger DORA/NIS2 third-party risk and concentration reviews. Adverse Trace will monitor for further victim disclosures, Icarus leak-site postings, and any vendor-side root-cause detail from Klue/CrowdStrike, and will update this advisory if the scope, severity or attribution changes.

---

[Read the original source →](https://www.darkreading.com/cyberattacks-data-breaches/scope-salesforce-attacks-expands-icarus-leaks-data?ref=f4n6.co.uk)

*Published via PulseTrace — Adverse Trace threat intelligence.*